CORS allows any origin
Access-Control-Allow-Origin is *.
Why it matters
Any website can read this response from a browser. That is fine for a truly public asset and risky for anything user-specific.
What to do
Restrict the header to trusted origins if the body is not public.
Reference
CORS controls which origins may read responses and must not expose credentialed data broadly.