CVE-2024-30148

CVSS 3.1 Score 4.1 of 10 (medium)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 284

Summary

CVE-2024-30148 is a newly disclosed vulnerability affecting HCL Leap. This issue arises from improper access controls on an endpoint within the platform, which allows certain admin users to bypass intended restrictions and import applications directly from the server's filesystem. This vulnerability could potentially lead to unauthorized software installation and execution, posing a significant risk to data security and system integrity. Organizations utilizing HCL Leap are advised to apply the necessary patches and implement access control best practices to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share