CVE-2025-59870: Improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59870?
CVE-2025-59870 is considered a high severity vulnerability due to the potential for exploitation through improper management of a static JWT signing secret.
How do I fix CVE-2025-59870?
To fix CVE-2025-59870, implement regular rotation of the JWT signing secret and ensure it is managed securely.
What software versions are affected by CVE-2025-59870?
CVE-2025-59870 affects HCL MyXalytics versions prior to v6.7 that do not adequately manage JWT signing secrets.
What are the consequences of exploiting CVE-2025-59870?
Exploitation of CVE-2025-59870 can lead to unauthorized access and data breaches due to the use of a static JWT signing secret.
Is there a workaround for CVE-2025-59870?
A temporary workaround for CVE-2025-59870 is to manually rotate the JWT signing secret until a permanent fix is applied.