Impact
HCL DevOps Loop is affected by an absence of critical HTTP security headers. The weakness corresponds to CWE-644. Without headers such as Content‑Security‑Policy, X-Frame-Options, X-Content-Type-Options, and X-XSS-Protection, web pages are more susceptible to clickjacking, MIME‑type sniffing, and cross‑site scripting attacks. This weakness could allow a malicious attacker to exploit tenant browsers that interact with the application.
Affected Systems
The affected vendor is HCLSoftware, product DevOps Loop. No specific version information is provided in the data, so any installation of DevOps Loop that has not been audited for correct header configuration is at risk.
Risk and Exploitability
The CVSS score of 3.7 indicates a low severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is from a client‑side perspective, where an attacker manipulates a user’s browser session or redirects to the application to take advantage of the missing headers. In the absence of additional mitigations, the risk to confidentiality, integrity, or availability is moderate and largely limited to the browser context.
OpenCVE Enrichment