HCL AION Inline Script Execution Vulnerability in Content Security Policy
Vulnerability
A vulnerability allowing inline script execution has been identified in HCL AION version 2.0. This issue arises from an improperly configured Content Security Policy (CSP) that fails to restrict inline scripts, potentially exposing the application to script-based attacks. The vulnerability was highlighted in a Dynamic Application Security Testing report.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of inline scripts, increasing the risk of cross-site scripting (XSS) attacks and other script-based vulnerabilities.
Remediation
Users can upgrade to HCL AION version 2.0.1, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION Product support team.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
