The Cross-domain policy can be limited / restricted else accessibility becomes wide open across any domain . Allowing access from all domains means that any domain can perform two-way interaction with the application which can be a security concern.
Issue/Introduction
Cross-Domain Policy for API Access
Resolution
CrossDomain is defaulted to being very permissive if not found in the configuration. Below settings make them least permissive: