{"authors":[{"id":null,"fullName":"Golinelli, Matteo","name":"Matteo","surname":"Golinelli","rank":1,"pid":{"id":{"scheme":"orcid_pending","value":"0000-0002-8743-0825"},"provenance":null}},{"id":null,"fullName":"Arshad, Elham","name":"Elham","surname":"Arshad","rank":2,"pid":{"id":{"scheme":"orcid_pending","value":"0000-0003-1256-2863"},"provenance":null}},{"id":null,"fullName":"Kashchuk, Dmytro","name":"Dmytro","surname":"Kashchuk","rank":3,"pid":null},{"id":"orcid_______::523a27c7b8617d3be78bc490d9d7b97d","fullName":"Crispo, Bruno","name":"Bruno","surname":"Crispo","rank":4,"pid":{"id":{"scheme":"orcid","value":"0000-0002-1252-8465"},"provenance":null}}],"openAccessColor":null,"publiclyFunded":false,"eoscIfGuidelines":null,"type":"publication","language":{"code":"und","label":"Undetermined"},"countries":[{"code":"IT","label":"Italy","provenance":null}],"subjects":[{"subject":{"scheme":"FOS","value":"0202 electrical engineering, electronic engineering, information engineering"},"provenance":null},{"subject":{"scheme":"keyword","value":"cache poisoning; CORS; cross-origin; cross-site requests; SOP;"},"provenance":null},{"subject":{"scheme":"FOS","value":"02 engineering and technology"},"provenance":null}],"mainTitle":"Mind the CORS","subTitle":null,"descriptions":["Cross-Origin Resource Sharing (CORS) is a mechanism to relax the security rules imposed by the Same-Origin Policy (SOP), which can be too restrictive for websites that rely on cross-site data exchange for their functioning. CORS allows trusting origins different from the website domain despite the presence of a strict SOP using a series of HTTP headers. This mechanism is supported by all modern browsers and is extensively adopted by websites. In CORS, servers are responsible for validating the value of the Origin header and deciding whether or not to trust it. For this reason, developers must be thorough in coding this process not to introduce security issues. We carried out a large-scale analysis on the Tranco Top 50k to measure the prevalence of various implementation flaws due to errors or simplifications in Origin validation and found that of the 6,862 websites using CORS, 2,014 (29.4%) have at least one flaw. We next exploit the vulnerabilities introduced by these CORS flaws in a realistic real-world scenario from the point of view of two attacker models with varying capability levels, evaluating the conditions necessary for a successful attack and its consequences. We show how these flaws enable attackers to perform Denial of Service and steal victims’ sensitive data and security tokens that can then be used to mount subsequent attacks. We conclude that CORS is an effective but complicated mechanism and its use should be carefully evaluated by website operators not to risk introducing severe security issues in their systems."],"publicationDate":"2023-11-01","publisher":"IEEE","embargoEndDate":null,"sources":["Crossref","IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA)"],"formats":["application/pdf"],"contributors":null,"coverages":null,"bestAccessRight":{"code":"c_abf2","label":"OPEN","scheme":"http://vocabularies.coar-repositories.org/documentation/access_rights/"},"container":{"name":"2023 5th IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA)","issnPrinted":null,"issnOnline":null,"issnLinking":null,"ep":"221","iss":null,"sp":"213","vol":null,"edition":null,"conferencePlace":null,"conferenceDate":null},"documentationUrls":null,"codeRepositoryUrl":null,"programmingLanguage":null,"contactPeople":null,"contactGroups":null,"tools":null,"size":null,"version":null,"geoLocations":null,"id":"doi_dedup___::6de2b1abd6e5bfd6295c7cd687978448","originalIds":["10.1109/tps-isa58951.2023.00035","50|doiboost____|6de2b1abd6e5bfd6295c7cd687978448","50|dblp________::d3b3b41be40977a6c25eb1489c33abb8","oai:iris.unitn.it:11572/399025","50|od______3432::8701befafc1766b80c91450bd148f90d","50|r3c4b2081b22::4b5ce03b6bc4ade6bee0048537e607d2","10.1109/TPS-ISA58951.2023.00035"],"pids":[{"scheme":"doi","value":"10.1109/tps-isa58951.2023.00035"},{"scheme":"handle","value":"11572/399025"}],"dateOfCollection":null,"lastUpdateTimeStamp":null,"indicators":{"citationImpact":{"citationCount":0.0,"influence":2.1746283E-9,"popularity":1.6835128E-9,"impulse":0.0,"citationClass":"C5","influenceClass":"C5","impulseClass":"C5","popularityClass":"C5"}},"projects":[{"id":"corda_____he::2623fda6b1fb70550cf4d7ad0c13f77f","code":"101070537","acronym":"CROSSCON","title":"Cross-platform Open Security Stack for Connected Devices","funder":"European Commission","pids":[{"scheme":"doi","value":"10.3030/101070537"}]},{"id":"corda_____he::9ce4795c43250f481c709ae85d41b183","code":"101086308","acronym":"DUCA","title":"Data Usage Control for empowering digital sovereignty for All citizens","funder":"European Commission","pids":[{"scheme":"doi","value":"10.3030/101086308"}]}],"organizations":[{"legalName":"University of Trento","acronym":"University of Trento","id":"openorgs____::db652e6496b6c6a08d25533f27864d04","pids":[{"scheme":"ROR","value":"https://ror.org/05trd4x28"},{"scheme":"OrgRef","value":"1949698"},{"scheme":"fundref","value":"501100004004"},{"scheme":"OrgReg","value":"IT0085"},{"scheme":"GRID","value":"grid.11696.39"},{"scheme":"ISNI","value":"0000000419370351"},{"scheme":"wikidata","value":"Q930528"},{"scheme":"Wikidata","value":"Q930528"},{"scheme":"mag_id","value":"193223587"},{"scheme":"FundRef","value":"501100004004"},{"scheme":"PIC","value":"999841954"}],"countries":[{"code":"IT","label":"Italy"}],"websiteurl":"http://www.unitn.it/en"}],"communities":[{"code":"eu-conexus","label":"European University for Smart Urban Coastal Sustainability","provenance":null}],"collectedFrom":[{"key":"opendoar____::72007983849f4fcb0ad565439834756b","value":"IRIS - Institutional Research Information System of the University of Trento"},{"key":"openaire____::081b82f96300b6a6e3d282bad31cb6e2","value":"Crossref"},{"key":"openaire____::d8b68cc0a53121f6f896883a7d60c1db","value":"DBLP"},{"key":"re3data_____::c4b2081b224be6b3e79d0e5e5556f631","value":"European Union Open Data Portal"}],"instances":[{"pids":[{"scheme":"doi","value":"10.1109/tps-isa58951.2023.00035"}],"license":"STM Policy #29","accessRight":{"code":"c_14cb","label":"CLOSED","scheme":"http://vocabularies.coar-repositories.org/documentation/access_rights/","openAccessRoute":null},"type":"Article","urls":["https://doi.org/10.1109/tps-isa58951.2023.00035"],"publicationDate":"2023-11-01","refereed":"peerReviewed","hostedBy":{"key":"openaire____::55045bd2a65019fd8e6741a755395c8c","value":"Unknown Repository"},"collectedFrom":{"key":"openaire____::081b82f96300b6a6e3d282bad31cb6e2","value":"Crossref"}},{"alternateIdentifiers":[{"scheme":"doi","value":"10.1109/tps-isa58951.2023.00035"}],"type":"Conference object","urls":["https://doi.org/10.1109/TPS-ISA58951.2023.00035","https://dblp.org/rec/conf/tpsisa/GolinelliAKC23.html"],"refereed":"nonPeerReviewed","hostedBy":{"key":"openaire____::d8b68cc0a53121f6f896883a7d60c1db","value":"DBLP"},"collectedFrom":{"key":"openaire____::d8b68cc0a53121f6f896883a7d60c1db","value":"DBLP"}},{"pids":[{"scheme":"handle","value":"11572/399025"}],"alternateIdentifiers":[{"scheme":"doi","value":"10.1109/tps-isa58951.2023.00035"},{"scheme":"urn","value":"2-s2.0-85186522488"},{"scheme":"urn","value":"W4391877204"}],"accessRight":{"code":"c_abf2","label":"OPEN","scheme":"http://vocabularies.coar-repositories.org/documentation/access_rights/","openAccessRoute":null},"type":"Conference object","urls":["https://doi.org/10.1109/TPS-ISA58951.2023.00035","https://hdl.handle.net/11572/399025","https://ieeexplore-ieee-org.ezp.biblio.unitn.it/document/10431636"],"publicationDate":"2023-01-01","refereed":"nonPeerReviewed","hostedBy":{"key":"opendoar____::72007983849f4fcb0ad565439834756b","value":"IRIS - Institutional Research Information System of the University of Trento"},"collectedFrom":{"key":"opendoar____::72007983849f4fcb0ad565439834756b","value":"IRIS - Institutional Research Information System of the University of Trento"}},{"alternateIdentifiers":[{"scheme":"doi","value":"10.1109/tps-isa58951.2023.00035"}],"type":"Conference object","urls":["http://dx.doi.org/10.1109/TPS-ISA58951.2023.00035"],"publicationDate":"2023-01-01","refereed":"nonPeerReviewed","hostedBy":{"key":"openaire____::55045bd2a65019fd8e6741a755395c8c","value":"Unknown Repository"},"collectedFrom":{"key":"re3data_____::c4b2081b224be6b3e79d0e5e5556f631","value":"European Union Open Data Portal"}}],"links":[{"header":{"relationType":"resultProject","relationClass":"isProducedBy","relatedIdentifier":"corda_____he::2623fda6b1fb70550cf4d7ad0c13f77f","relatedRecordType":"project","relationProvenance":"iis","trust":"0.897"},"collectedfrom":[{"dsId":"openaire____::3f264f93cf3b0cfc4ede188a6300455c","dsName":"CORDA - COmmon Research DAta Warehouse - Horizon Europe"}],"projectTitle":"Cross-platform Open Security Stack for Connected Devices","code":"101070537","funding":{"funder":{"id":"ec__________::EC","shortname":"EC","name":"European Commission","jurisdiction":{"code":"EU","label":"European Union"},"pid":null},"level0":{"id":"ec__________::EC::HE","description":"Horizon Europe Framework Programme","name":"HE"},"level1":{"id":"ec__________::EC::HE::HORIZON-RIA","description":"HORIZON  Research and Innovation Actions","name":"HORIZON-RIA"},"level2":{"id":null,"description":null,"name":null}},"startDate":"2022-11-01","endDate":"2025-10-31"},{"header":{"relationType":"resultProject","relationClass":"isProducedBy","relatedIdentifier":"corda_____he::9ce4795c43250f481c709ae85d41b183","relatedRecordType":"project","relationProvenance":"iis","trust":"0.897"},"collectedfrom":[{"dsId":"openaire____::3f264f93cf3b0cfc4ede188a6300455c","dsName":"CORDA - COmmon Research DAta Warehouse - Horizon Europe"}],"projectTitle":"Data Usage Control for empowering digital sovereignty for All citizens","code":"101086308","funding":{"funder":{"id":"ec__________::EC","shortname":"EC","name":"European Commission","jurisdiction":{"code":"EU","label":"European Union"},"pid":null},"level0":{"id":"ec__________::EC::HE","description":"Horizon Europe Framework Programme","name":"HE"},"level1":{"id":"ec__________::EC::HE::HORIZON-TMA-MSCA-SE","description":"HORIZON TMA MSCA Staff Exchanges","name":"HORIZON-TMA-MSCA-SE"},"level2":{"id":null,"description":null,"name":null}},"startDate":"2023-01-01","endDate":"2026-12-31"}],"otherTitles":null,"green":true,"inDiamondJournal":false,"isGreen":true,"isInDiamondJournal":false}