HCL AION JWT Token Expiry Too Long Vulnerability
Vulnerability
A vulnerability exists in HCL AION version 2 due to JWT tokens having an excessively long expiry time. This could lead to token misuse, allowing unauthorized access if the token is compromised.
Impact
Excessively long token expiry times could increase the risk of token theft leading to unauthorized access.
Added: Jan 19, 2026, 6:35 PM
Updated: Jan 19, 2026, 6:35 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
4.7remediation
0.0relevance
2.3threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
