3.2

CVE-2024-30127

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HcltechHcl Leap Version < 9.3.9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.015
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@hcl.com 3.2 1.5 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
CWE-524 Use of Cache Containing Sensitive Information

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.