Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.
History

Thu, 24 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.
Title HCL Leap is affected by improper access control
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published: 2025-04-24T16:10:00.714Z

Updated: 2025-04-24T17:41:59.455Z

Reserved: 2024-03-22T23:57:26.413Z

Link: CVE-2024-30148

cve-icon Vulnrichment

Updated: 2025-04-24T17:41:46.638Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-24T16:15:28.290

Modified: 2025-04-29T13:52:47.470

Link: CVE-2024-30148

cve-icon Redhat

No data.