Missing no cache headers in HCL Leap permits user directory information to be cached.
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Hcl_leap | Hcltech | * | 9.3.4 (excluding) |