CVE-2025-31991: HCL DevOps Velocity is susceptible to brute-force attacks
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit. This vulnerability is fixed in 5.1.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HCL DevOps Velocityto a version that resolves this vulnerability.Fixed in 5.1.7
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31991?
The severity of CVE-2025-31991 is significant as it allows for brute-force attacks on user login due to improper rate limiting.
How do I fix CVE-2025-31991?
To fix CVE-2025-31991, update HCL DevOps Velocity to version 5.1.7 or later which addresses the vulnerability.
What impact does CVE-2025-31991 have on system security?
CVE-2025-31991 can lead to unauthorized access if an attacker succeeds in brute-forcing user credentials.
Is CVE-2025-31991 applicable to all versions of HCL DevOps Velocity?
CVE-2025-31991 primarily affects versions of HCL DevOps Velocity prior to 5.1.7.
What should organizations using HCL DevOps Velocity do regarding CVE-2025-31991?
Organizations using HCL DevOps Velocity should prioritize updating to version 5.1.7 or later to mitigate the risk associated with CVE-2025-31991.