Barrion Docs
Passive Scanning

Cross-Origin Resource Sharing (CORS)

What Barrion checks when it evaluates how your site handles requests from other websites.

Barrion checks how your site controls access from other websites. CORS (Cross-Origin Resource Sharing) is the browser mechanism that governs whether external websites can read your API responses. Misconfigured CORS can expose user data to websites they did not intend to share it with.

What Barrion Checks

Origin Access Control

Barrion checks whether your site restricts which external websites can access its responses. If your site allows any website to read its responses (using a wildcard policy), sensitive data returned by your API could be read by a malicious site the user happens to visit.

Severity: High

Credentialed Cross-Origin Access

Barrion checks whether your site allows other websites to make requests on behalf of your authenticated users. If this is enabled alongside an overly permissive origin policy, attackers can make authenticated requests to your API from any website.

Severity: High

CORS Headers Configuration

Barrion checks several additional CORS headers that affect how browsers cache and handle cross-origin requests, including allowed request headers, exposed response headers, and preflight caching. Issues here typically affect performance or can cause legitimate cross-origin requests to fail.

Severity: Low to Medium

Cross-Origin Isolation Headers

Barrion checks for advanced isolation headers (COEP, COOP, CORP) that provide protection against sophisticated browser-level attacks. These are best practice for high-security applications.

Severity: Low

What to Do

CORS is configured in your application or API layer. Share failing findings with your development team. The most important findings to address are those flagged as High severity: overly permissive origin policies on authenticated endpoints. Barrion's finding details include the specific headers detected to help your team make targeted changes.