HCL Hive 存在一个信息泄露漏洞,发现其 Swagger 文档被公开暴露。尽管未发现任何敏感信息(例如凭据、个人身份信息),但向未认证用户暴露 API 文档仍可能增加整体攻击面。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCLSoftware | HCL Hive | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCLSoftware | HCL Hive | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-21752 | 7.5 HIGH | HCL Hive is affected by a use of vulnerable third-party components |
| CVE-2025-68825 | 7.5 HIGH | HCL Hive is affected by incorrect default permissions |
| CVE-2026-21751 | 7.4 HIGH | HCL Hive is affected by use of a cryptographic primitive with a risky implementation |
| CVE-2026-21756 | 7.2 HIGH | HCL Hive is affected by a broken access control vulnerability |
| CVE-2025-68833 | 5.3 MEDIUM | HCL Hive is affected by use of a cryptographic primitive with a risky implementation |
| CVE-2026-21755 | 5.3 MEDIUM | HCL Hive is affected by a missing rate limit |
No comments yet