HCL DevOps Deploy Cross-Origin Resource Sharing Vulnerability Allowing Privileged Actions and Information Retrieval

Vulnerability

A vulnerability exists in HCL DevOps Deploy due to improper Cross-Origin Resource Sharing (CORS) configuration. The application does not restrict domain names to trusted sources, potentially allowing attackers to perform privileged actions and access sensitive information.

Impact

Exploitation of this vulnerability could lead to unauthorized privileged actions and exposure of sensitive information.

Added: Jul 9, 2026, 10:36 AM
Updated: Jul 9, 2026, 10:36 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
5.2
exploitability
5.8
remediation
0.0
relevance
9.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.