CVE-2024-30127: HCL Leap is affected by missing "no cache" headers
Published Apr 24, 2025
·Updated
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
Affected Software
2 affected components
HCL Leap
hcltech Hcl Leap<9.3.9
Event History
Apr 24, 2025
CVE Published
via MITRE·08:35 PM
Data Sourced
via MITRE·08:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30127?
CVE-2024-30127 has been rated as a medium severity vulnerability due to the potential exposure of sensitive data.
2
How do I fix CVE-2024-30127?
To fix CVE-2024-30127, implement the appropriate 'no-cache' headers in the HCL Leap configuration to prevent sensitive data from being cached.
3
What type of data is affected by CVE-2024-30127?
CVE-2024-30127 affects sensitive data that can be cached, potentially leading to unauthorized access.
4
Which software versions are affected by CVE-2024-30127?
CVE-2024-30127 affects the HCL Leap software without specifying particular versions.
5
How can I identify if CVE-2024-30127 is present in my system?
You can identify CVE-2024-30127 in your system by checking the response headers for the presence of 'no-cache' directives in HCL Leap.