20–30 min Updated

Cross-Origin Resource Sharing

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Overly permissive CORS policies can allow malicious websites to access your APIs and steal user data.

Prevalence
Common
Exploitability
Easy
Impact
Harmful

What is a CORS misconfiguration?

Cross-Origin Resource Sharing (CORS) is a browser mechanism that lets a server relax the same-origin policy for chosen origins. A CORS misconfiguration is a security misconfiguration vulnerability in which a server trusts too many origins, for example by reflecting any origin alongside credentials, allowing a malicious website to read a logged-in user's data from your API.

What you'll learn

  • How CORS relaxes the same-origin policy for chosen origins
  • Why reflecting any origin alongside credentials exposes user data
  • How to allow only the origins, methods and headers you trust

Where this lesson counts

OWASP Top 10

  • Cross-Origin Resource Sharing lab

    A SecureBank developer ships a debugging shortcut that lets any origin call the API with credentials. Follow Vic from his online banking session to Mal's Kitchen, a recipe blog whose hidden script quietly requests his balance, transactions and personal details.

  • How to prevent Cross-Origin Resource Sharing

    The prevention guide covers six approaches:

    • Use Secure Defaults
    • Implement Strict Origin Controls
    • Enumerate Origins Explicitly
    • Restrict HTTP Methods
    • Control Allowed Headers
    • Environment-Specific Configuration
  • Cross-Origin Resource Sharing quiz

    Four questions. Passing marks the lesson complete.

Sources

  • Cross-Site Request Forgery

    If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.

  • Cross-Site Script Inclusion

    If you are putting sensitive data in your JavaScript files, an attacker is probably stealing it.

  • Information Leakage

    Revealing system information helps an attacker learn about your tech stack.

  • Subdomain Squatting

    Attackers will steal dangling subdomains to deliver malware and perform phishing attacks.