5.3
CVE-2026-21762
- EPSS 0.17%
- Veröffentlicht 17.07.2026 17:10:33
- Zuletzt bearbeitet 13.08.2026 12:51:58
- Erkennungen
Missing HTTP Security Headers in DevOps Loop
HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Devops Loop Version 2.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.069 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| psirt@hcl.com | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax
The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132296