Missing no cache headers in HCL Leap permits sensitive data to be cached.
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Domino_leap | Hcltech | 1.1 (including) | 1.1.2 (excluding) |