CORS Misconfiguration

CORS misconfiguration in C#

Description

Allowing arbitrary request origins together with credentials can let an untrusted website read protected responses when the browser sends authentication credentials. Whether cookies are sent also depends on client settings, SameSite, and browser policy.

Combining AllowAnyOrigin() with AllowCredentials() is not a valid credentialed CORS configuration. Using SetIsOriginAllowed(_ => true) to bypass that restriction trusts arbitrary origins. CORS does not replace authentication and authorization on the server.

Potential impact

  • If the user's authentication cookies are sent, an untrusted origin can read authenticated responses and steal data.

Remediation

Allow only explicitly trusted origins with a defined scheme, host, and port, and allow credentials only when necessary. Do not reflect arbitrary origins, and retain server-side authentication and authorization.

Examples

Each excerpt configures a separate CorsPolicyBuilder. Policy registration and endpoint application are omitted.

Before

csharp
policy.SetIsOriginAllowed(_ => true).AllowCredentials();

After

csharp
policy.WithOrigins("https://app.example.com").AllowCredentials();

Explanation:

  • Before: Trusting every origin and allowing credentials lets untrusted origins read responses when authentication credentials are sent.
  • After: Use explicitly trusted origins and do not reflect arbitrary Origin headers.

References