My project was scanned by Checkmarx, and all the controller methods had this low level risk: Spring Overly Permissive Cross Origin Resource Sharing Policy.
public JSONObject example(@RequestBody JSONObject param) {...}
The report doesn't say anything about the problem. Neither why it cause the risk, nor how to fix it.
We have CORS setting in the application.yaml:
security:
cors:
allowed-origins:
https://example1.com,
https://example2.com
allowed-methods:
GET,
POST,
PUT
But still showing this vulnerability. Is there anyway to prevent Checkmarx showing this?