HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potential security risk, as it grants elevated permissions within the container environment. Aligning container configurations with security best practices requires minimizing privileges and avoiding root-level execution wherever possible.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcl
Hcl aion |
|
| CPEs | cpe:2.3:a:hcl:aion:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hcl
Hcl aion |
Tue, 17 Mar 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL AION is affected by a vulnerability where container base images are not properly authenticated. This may expose the system to potential security risks such as usage of untrusted container images, which could lead to unintended behaviour or security impact. | HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potential security risk, as it grants elevated permissions within the container environment. Aligning container configurations with security best practices requires minimizing privileges and avoiding root-level execution wherever possible. |
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 | |
| Metrics |
ssvc
|
Mon, 16 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL AION is affected by a vulnerability where container base images are not properly authenticated. This may expose the system to potential security risks such as usage of untrusted container images, which could lead to unintended behaviour or security impact. | |
| Title | Multiple security vulnerabilities affect HCL AION | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published: 2026-03-16T12:35:06.222Z
Updated: 2026-03-17T10:57:54.993Z
Reserved: 2025-06-18T14:00:43.106Z
Link: CVE-2025-52638
Updated: 2026-03-16T14:44:47.711Z
Status : Analyzed
Published: 2026-03-16T14:17:59.610
Modified: 2026-03-27T17:27:23.670
Link: CVE-2025-52638
No data.