'Cross-origin stopped after adding “X-Content-Type-Options: nosniff” on WAF level

I used to get use cross-origin pages from dev.xxx.com to payment.xxx.com page using jQuery calling in asp.net MVC pages. Due to PCI compliance system admin added x-content-type-options header to nosniff in WAF. Now pages not loading from dev.xxx.com to payment.xxx.com.

  Cross-Origin Read Blocking (CORB) blocked cross-origin response https://payment.xxx.com/Pay/SetMemberSession?
jsoncallback=jQuery34106238155481903753_1649110660650&wizardId=3440214&jsonp=true&_=
1649110660651 with MIME type text/html. See https://www.chromestatus.com/feature/5629709824032768 for more details.

Is there any alternate to bypass WAF and get it done?



Sources

This article follows the attribution requirements of Stack Overflow and is licensed under CC BY-SA 3.0.

Source: Stack Overflow

Solution Source