Managing external identities to enable secure access for partners, customers, and other non-employees
Pen Test Failed Due to Cross-Origin Resource Sharing (CORS) Trusting Arbitrary Origins in Azure AD B2C Authentication Flow
The customer's logins are integrated with Azure AD B2C authentication flow. The frontend application is hosted on Azure Static Web Apps, while the backend API communicates with Azure App Services through the Azure API Management service.
Following a pen test conducted by our organization, a vulnerability was identified where the site improperly trusts arbitrary domains.
The response included the client-specified domain in the Access-Control-Allow-Origin header, bypassing the Same Origin Policy.
The vulnerability is worsened by the Access-Control-Allow-Credentials header being set to true, which allows any domain to interact with the application and request authentication or authorisation keys, as shown below.
HTTP/1.1 200 OK
Cache-Control: no-store, must-revalidate, no-cache
Content-Type: application/json; charset=utf-8
Set-Cookie: x-ms-cpim-trans=; domain=stoltuatb2c.b2clogin.com; expires=Thu, 17-Sep2015 12:45:13 GMT; path=/; SameSite=None; secure; HttpOnly
x-ms-gateway-requestid: aa2dea26-a29f-4c1e-9c9e-c4f45a9570eb
Access-Control-Allow-Origin: https://ptp.sh
Access-Control-Expose-Headers: Content-Length, Content-Encoding
Access-Control-Allow-Credentials: true
Access-Control-Allow-Methods: POST, OPTIONS
X-Frame-Options: DENY
Public: OPTIONS,TRACE,GET,HEAD,POST
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Allow: OPTIONS
Allow: TRACE
Allow: GET
Allow: HEAD
Allow: POST
Date: Wed, 17 Sep 2025 12:45:12 GMT
Content-Length: 2680
(…snipped for brevity…)
Additionally, the "Referrer-Policy" security header was missing in the HTTP response, which could potentially expose sensitive information by including the full URL of the referring page in requests.
Please assist us in understanding how to manage this HTTP header and resolve the issue in Azure AD B2C end.