Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech devops Loop |
|
| Vendors & Products |
Hcltech
Hcltech devops Loop |
Wed, 05 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive resources and perform actions with elevated privileges. | |
| Title | HCL DevOps Loop is susceptible to an improper authentication vulnerability | |
| Weaknesses | CWE-347 CWE-613 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2025-11-06T21:20:55.355Z
Reserved: 2025-08-12T07:00:17.743Z
Link: CVE-2025-55278
Updated: 2025-11-06T21:20:51.347Z
Status : Deferred
Published: 2025-11-05T23:16:05.147
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-55278
No data.
OpenCVE Enrichment
Updated: 2025-11-06T10:06:51Z