CVE Vulnerabilities

CVE-2024-23560

Improper Preservation of Permissions

Published: Apr 15, 2024 | Modified: Apr 11, 2025
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Hcl_devops_deploy Hcltechsw 8.0.0.0 (including) 8.0.1 (excluding)
Hcl_launch Hcltechsw 7.0.0.0 (including) 7.0.5.21 (excluding)
Hcl_launch Hcltechsw 7.1.0.0 (including) 7.1.2.17 (excluding)
Hcl_launch Hcltechsw 7.2.0.0 (including) 7.2.3.10 (excluding)
Hcl_launch Hcltechsw 7.3.0.0 (including) 7.3.2.5 (excluding)

References