CVE-2025-59874: HCL Hive Telco Observability is affected by a Required directives missing from the CSP .
HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the Keycloak component (or the fronting web application) to include the missing required directives in the Content-Security-Policy HTTP header or meta tag. Ensure all essential directives required by your security policy are present and correctly scoped, validate the policy in a test environment, and deploy the updated policy to production.
Keycloak (HCL Hive Telco Observability) Content-Security-Policy = Add required directives
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59874?
The severity of CVE-2025-59874 is rated high with a score of 8.1.
What are the risks associated with CVE-2025-59874?
CVE-2025-59874 poses risks of content spoofing and data breaches due to missing directives in the Content Security Policy.
How do I fix CVE-2025-59874?
To fix CVE-2025-59874, ensure that all required directives are included in your Content Security Policy for the application.
Which software is affected by CVE-2025-59874?
CVE-2025-59874 affects HCL Hive Telco Observability and the Red Hat Keycloak components of the web application.
What is the impact of missing directives in the CSP related to CVE-2025-59874?
Missing directives in the CSP related to CVE-2025-59874 can lead to increased vulnerability to attacks such as cross-site scripting.