{"id":"CVE-2025-31991","title":"Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.","summary":"Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N","cwe":["CWE-307"],"vendor":"hcltech","product":"devops_velocity","affected":["devops_velocity < 5.1.7"],"patched":["devops_velocity 5.1.7"],"published":"2026-04-13","updated":"2026-07-07","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-31991","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130138","label":"psirt@hcl.com"}],"tags":["nvd"],"epss":0.00228,"epssPercentile":0.13752,"ingestedAt":"2026-07-07T18:42:24.227Z","slug":"CVE-2025-31991","body":"## Overview\n\nRate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.\n\n## Affected\n\n- `devops_velocity < 5.1.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `devops_velocity 5.1.7`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}