Cross-Origin Resource Sharing
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Overly permissive CORS policies can allow malicious websites to access your APIs and steal user data.
- Prevalence
- Common
- Exploitability
- Easy
- Impact
- Harmful
What is a CORS misconfiguration?
Cross-Origin Resource Sharing (CORS) is a browser mechanism that lets a server relax the same-origin policy for chosen origins. A CORS misconfiguration is a security misconfiguration vulnerability in which a server trusts too many origins, for example by reflecting any origin alongside credentials, allowing a malicious website to read a logged-in user's data from your API.
What you'll learn
- How CORS relaxes the same-origin policy for chosen origins
- Why reflecting any origin alongside credentials exposes user data
- How to allow only the origins, methods and headers you trust
Where this lesson counts
OWASP Top 10
Default accounts, verbose errors, unhardened parsers and permissive headers leave the door open.
Learn more about A02This lesson includes
-
Cross-Origin Resource Sharing lab
A SecureBank developer ships a debugging shortcut that lets any origin call the API with credentials. Follow Vic from his online banking session to Mal's Kitchen, a recipe blog whose hidden script quietly requests his balance, transactions and personal details.
-
How to prevent Cross-Origin Resource Sharing
The prevention guide covers six approaches:
- Use Secure Defaults
- Implement Strict Origin Controls
- Enumerate Origins Explicitly
- Restrict HTTP Methods
- Control Allowed Headers
- Environment-Specific Configuration
-
Cross-Origin Resource Sharing quiz
Four questions. Passing marks the lesson complete.
Sources
- Cross-Origin Resource Sharing (CORS) MDN
- CORS misconfigurations PortSwigger
- Same-origin policy MDN
- Cross-Origin Resource Sharing (CORS) web.dev
- CORS specification WHATWG
Related lessons
Browse all 45 lessons
Cross-Site Request Forgery
If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.
Cross-Site Script Inclusion
If you are putting sensitive data in your JavaScript files, an attacker is probably stealing it.
Information Leakage
Revealing system information helps an attacker learn about your tech stack.
Subdomain Squatting
Attackers will steal dangling subdomains to deliver malware and perform phishing attacks.