Property
Languagehcl
Severitylow
CWECWE-942: Permissive Cross-domain Policy with Untrusted Domains
OWASPA05:2021 - Security Misconfiguration
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The configuration allows all external origins (’*’) to access your Azure App Service via CORS. This means any website can make requests to your app, exposing it to potential abuse.

Impact#

If exploited, malicious websites could interact with your app’s APIs, potentially stealing sensitive data or performing unauthorized actions on behalf of users. This weakens your app’s defenses and increases the risk of data leaks or account compromise.