HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hcl_devops_deploy | Hcltechsw | 8.0.0.0 (including) | 8.0.1 (excluding) |
Hcl_launch | Hcltechsw | 7.0.0.0 (including) | 7.0.5.21 (excluding) |
Hcl_launch | Hcltechsw | 7.1.0.0 (including) | 7.1.2.17 (excluding) |
Hcl_launch | Hcltechsw | 7.2.0.0 (including) | 7.2.3.10 (excluding) |
Hcl_launch | Hcltechsw | 7.3.0.0 (including) | 7.3.2.5 (excluding) |