Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive resources and perform actions with elevated privileges.
References
Configurations
No configuration.
History
05 Nov 2025, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-05 23:16
Updated : 2025-11-06 19:45
NVD link : CVE-2025-55278
Mitre link : CVE-2025-55278
CVE.ORG link : CVE-2025-55278
JSON object : View
Products Affected
No product.
