CVE-2025-55278 - HCL DevOps Loop is susceptible to an improper authentication vulnerability
CVE ID : CVE-2025-55278
Published : Nov. 5, 2025, 11:16 p.m. | 2 hours, 50 minutes ago
Description : Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive resources and perform actions with elevated privileges.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Nov. 5, 2025, 11:16 p.m. | 2 hours, 50 minutes ago
Description : Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive resources and perform actions with elevated privileges.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...