Impact
An improper CORS configuration in HCL DevOps Loop allows requests originating from untrusted domains to access application resources without adequate authorization. This can lead to data exposure or unverified interactions with the application, compromising confidentiality and integrity of exposed data. The weakness corresponds to CWE-942, offensive CORS misconfiguration.
Affected Systems
The vulnerability affects HCL Software’s DevOps Loop platform. No specific versions are listed, so any deployment of this product may be at risk.
Risk and Exploitability
The CVSS score of 4.2 indicates low severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to craft a malicious web page or script that targets the application’s endpoints from an untrusted origin, exploiting the permissive CORS policy to read or manipulate data.
OpenCVE Enrichment