3.2

CVE-2023-37516

HCL Leap is affected by missing "no cache" headers

Missing "no cache" headers in HCL Leap permits user directory information to be cached.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HcltechHcl Leap Version < 9.3.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.173
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@hcl.com 3.2 1.5 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
CWE-524 Use of Cache Containing Sensitive Information

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.