S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Misconfiguration·Updated Jan 3, 2024

HTTP Server Cross-Origin Resource Sharing (CORS) Scanner

HTTP Server Cross-Origin Resource Sharing (CORS) Scanner

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
1.3k
Vulnerabilities Found
confirmed findings
Detail

Tests an http server for Cross-Origin Resource Sharing (CORS), a way for domains to explicitly opt in to having certain methods invoked by another domain.

The script works by setting the Access-Control-Request-Method header field for certain enumerated methods in OPTIONS requests, and checking the responses.

Solution Advice

Only use components that do not have known vulnerabilities, only use components that, when combined, do not introduce a security vulnerability, and ensure that a misconfiguration does not cause any vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

HTTP Server Cross-Origin Resource Sharing (CORS) Scanner | S4E