CVE-2025-62328: HCL Nomad server on Domino is affected by a missing default frame-ancestors directive
Published Mar 11, 2026
·Updated
HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors.
Affected Software
1 affected component
HCL Nomad
Event History
Mar 11, 2026
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62328?
CVE-2025-62328 is considered a moderate severity vulnerability due to the potential for exposing sensitive information.
2
How do I fix CVE-2025-62328?
To fix CVE-2025-62328, configure the frame-ancestors directive in the Content-Security-Policy header for HCL Nomad server on Domino.
3
What software is affected by CVE-2025-62328?
CVE-2025-62328 affects the HCL Nomad server on Domino.
4
What type of attack is possible due to CVE-2025-62328?
CVE-2025-62328 could allow an attacker to obtain sensitive information through unspecified vectors.
5
Is there a known exploit for CVE-2025-62328?
As of now, there is no public knowledge of an exploit specifically targeting CVE-2025-62328.