Pen Test Failed Due to Cross-Origin Resource Sharing (CORS) Trusting Arbitrary Origins in Azure AD B2C Authentication Flow

Naveen Kumar (NVK) 20 Reputation points
2025-11-06T13:23:32.43+00:00

The customer's logins are integrated with Azure AD B2C authentication flow. The frontend application is hosted on Azure Static Web Apps, while the backend API communicates with Azure App Services through the Azure API Management service.

Following a pen test conducted by our organization, a vulnerability was identified where the site improperly trusts arbitrary domains.

The response included the client-specified domain in the Access-Control-Allow-Origin header, bypassing the Same Origin Policy.

The vulnerability is worsened by the Access-Control-Allow-Credentials header being set to true, which allows any domain to interact with the application and request authentication or authorisation keys, as shown below.

HTTP/1.1 200 OK

Cache-Control: no-store, must-revalidate, no-cache

Content-Type: application/json; charset=utf-8

Set-Cookie: x-ms-cpim-trans=; domain=stoltuatb2c.b2clogin.com; expires=Thu, 17-Sep2015 12:45:13 GMT; path=/; SameSite=None; secure; HttpOnly

x-ms-gateway-requestid: aa2dea26-a29f-4c1e-9c9e-c4f45a9570eb

Access-Control-Allow-Origin: https://ptp.sh

Access-Control-Expose-Headers: Content-Length, Content-Encoding

Access-Control-Allow-Credentials: true

Access-Control-Allow-Methods: POST, OPTIONS

X-Frame-Options: DENY

Public: OPTIONS,TRACE,GET,HEAD,POST

Strict-Transport-Security: max-age=31536000; includeSubDomains

X-Content-Type-Options: nosniff

X-XSS-Protection: 1; mode=block

Allow: OPTIONS

Allow: TRACE

Allow: GET

Allow: HEAD

Allow: POST

Date: Wed, 17 Sep 2025 12:45:12 GMT

Content-Length: 2680

(…snipped for brevity…)

Additionally, the "Referrer-Policy" security header was missing in the HTTP response, which could potentially expose sensitive information by including the full URL of the referring page in requests.

Please assist us in understanding how to manage this HTTP header and resolve the issue in Azure AD B2C end. 

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.