Fix a wildcard CORS origin with cookies
cors-wildcard-creds
A wildcard allow-origin combined with credentials is rejected by browsers, so the cross-origin calls you meant to allow just fail. Name the origin.
Why this matters
Your server sends Access-Control-Allow-Origin: * with credentials, but browsers block this combination per the CORS spec. The attack cannot succeed. Still a misconfiguration worth fixing.
Web servers
Frameworks
Nginx
- 1 Never combine Access-Control-Allow-Origin: * with Allow-Credentials: true
- 2 Use a map to allowlist specific origins
nginx
# Remove:
# add_header Access-Control-Allow-Origin * always;
# add_header Access-Control-Allow-Credentials true always;
# Replace with origin allowlist (see cors-origin-reflect fix)Does your app still have this?
Scan your domain