HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
Nonces should be used for the present occasion and only once.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Myxalytics | Hcltech | 6.2 (including) | 6.2 (including) |
| Myxalytics | Hcltech | 6.3 (including) | 6.3 (including) |
| Myxalytics | Hcltech | 6.4 (including) | 6.4 (including) |
| Myxalytics | Hcltech | 6.5 (including) | 6.5 (including) |
| Myxalytics | Hcltech | 6.6 (including) | 6.6 (including) |
| Myxalytics | Hcltech | 6.7 (including) | 6.7 (including) |