Access-Control-Allow-Origin allowed access from the requested origin


I run into an issue where this path /auth/realms/development/.well-known/openid-configuration scan by vulnerability tools which it allowed access from others requested origin.
I had have the below settings on the web origins but its still same issues from my vulneribility scan.
Any ideas on how to solve this?