CVE Vulnerabilities

CVE-2023-37516

Use of Cache Containing Sensitive Information

Published: Apr 24, 2025 | Modified: Nov 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Missing no cache headers in HCL Leap permits user directory information to be cached.

Weakness

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Hcl_leap Hcltech * 9.3.4 (excluding)

Potential Mitigations

References