Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
Vulnerability Description
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
N/A
Vulnerability Title
HCL MyXalytics 安全漏洞
Vulnerability Description
HCL MyXalytics是印度HCL公司的一款分析类软件产品。用于进行数据分析等相关工作。 HCL MyXalytics v6.7版本存在安全漏洞,该漏洞源于静态JWT签名密钥管理不当且缺乏轮换,可能导致安全风险。
CVSS Information
N/A
Vulnerability Type
N/A