STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must specify allowed origins when using Cross-Origin Resource Sharing (CORS).

DISA Rule

SV-274613r1143646_rule

Vulnerability Number

V-274613

Group Title

SRG-APP-000251

Rule Version

SRG-APP-000251-API-000525

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to specify allowed origins when using CORS.

Check Contents

If CORS is not in use, this requirement is not applicable.

Verify the API specifies origins when using CORS.

If the API is using CORS and does not specify allowed origins, this is a finding.

Vulnerability Number

V-274613

Documentable

False

Rule Version

SRG-APP-000251-API-000525

Severity Override Guidance

If CORS is not in use, this requirement is not applicable.

Verify the API specifies origins when using CORS.

If the API is using CORS and does not specify allowed origins, this is a finding.

Check Content Reference

M

Target Key

5703