← back
CVE-2025-59874highCWE-1027

HCL Hive Telco Observability is affected by  a Required directives missing from the CSP .

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
In short

HCL Hive Telco Observability has incomplete security rules (Content Security Policy) in its Keycloak login component, which can allow attackers to inject malicious code into web pages.

Technical detail

The Keycloak component lacks required CSP directives, enabling content injection attacks. An attacker can exploit this to execute arbitrary JavaScript in users' browsers if the application processes untrusted input without proper directive enforcement.

Summary generated and translated by AI from the official description.
HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected products
HCL · Hive