HCL DevOps Deploy/Launch Vulnerable to HTML Injection
CVE-2024-42195

6.8MEDIUM

Key Information:

Vendor
CVE Published:
5 December 2024

What is CVE-2024-42195?

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

Affected Version(s)

DevOps Deploy / Launch 7.0 - 7.0.5.24, 7.1 - 7.1.2.20, 7.2 - 7.2.3.13, 7.3 - 7.3.2.8, 8.0 - 8.0.1.3

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.