Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored…
mozilla·CWE-346·Published 2018-06-11