Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-55278

Опубликовано: 05 нояб. 2025
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive resources and perform actions with elevated privileges.

EPSS

Процентиль: 8%
0.00029
Низкий

8.1 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 8.1
github
3 месяца назад

Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive resources and perform actions with elevated privileges.

EPSS

Процентиль: 8%
0.00029
Низкий

8.1 High

CVSS3

Дефекты

CWE-347