Checkmarx: Spring Overly Permissive Cross Origin Resource Sharing Policy in Java

Viewed 62

My project was scanned by Checkmarx, and all the controller methods had this low level risk: Spring Overly Permissive Cross Origin Resource Sharing Policy.

public JSONObject example(@RequestBody JSONObject param) {...}

The report doesn't say anything about the problem. Neither why it cause the risk, nor how to fix it.

We have CORS setting in the application.yaml:

security:
  cors:
    allowed-origins: 
      https://example1.com,
      https://example2.com
    allowed-methods:
      GET,
      POST,
      PUT

But still showing this vulnerability. Is there anyway to prevent Checkmarx showing this?

0 Answers
Related