Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41413 | HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any web domain and enable cache poisoning attacks. |
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2024-08-02T17:16:30.442Z
Reserved: 2023-07-06T16:12:30.394Z
Link: CVE-2023-37526
Updated: 2024-08-02T17:16:30.442Z
Status : Deferred
Published: 2024-05-14T13:20:18.717
Modified: 2026-06-17T06:08:22.907
Link: CVE-2023-37526
No data.
OpenCVE Enrichment
No data.
-
CWE-942
Permissive Cross-domain Security Policy with Untrusted Domains
EUVD