Executive brief
HCL DevOps Loop, a tool used for streamlining development workflows, is affected by a security misconfiguration in how it handles requests from different web domains. This flaw could allow an unauthorized third-party website to interact with the application, potentially leading to the exposure of sensitive internal resources or data. While the risk is mitigated by specific technical requirements, it could compromise the privacy of development operations.
Technical details
HCL DevOps Loop version 2.0.0 contains a Cross-Origin Resource Sharing (CORS) misconfiguration (CWE-942). The application implements a permissive cross-domain policy that fails to properly restrict which origins can access its resources. An authenticated attacker with network access could leverage this misconfiguration to perform unauthorized cross-origin requests. If successful, this allows an untrusted domain to read sensitive data or interact with application resources that should be restricted to the same-origin policy. The vulnerability has a CVSS score of 4.2, reflecting a high complexity of exploitation and the requirement for low-level user privileges.
Affected products
- HCL Software DevOps Loop 2.0.0
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory