HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.
2023-04-02T21:15:08.120
2025-02-19T16:15:35.533
Modified
CVSSv3.1: 9.6 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | hcltech | hcl_compass | ≤ 2.0.3 | Yes |
| Application | hcltech | hcl_compass | < 2.2.1 | Yes |