CVE Vulnerabilities

CVE-2024-23561

Insecure Storage of Sensitive Information

Published: Apr 15, 2024 | Modified: Apr 11, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Hcl_devops_deployHcltechsw8.0.0.0 (including)8.0.1 (excluding)
Hcl_launchHcltechsw7.0.0.0 (including)7.0.5.21 (excluding)
Hcl_launchHcltechsw7.1.0.0 (including)7.1.2.17 (excluding)
Hcl_launchHcltechsw7.2.0.0 (including)7.2.3.10 (excluding)
Hcl_launchHcltechsw7.3.0.0 (including)7.3.2.5 (excluding)

References