Information Disclosure Vulnerability in HCL DevOps Deploy and HCL Launch
CVE-2026-67071

6.5MEDIUM

What is CVE-2026-67071?

HCL DevOps Deploy and HCL Launch have a vulnerability that exposes sensitive data through improper handling of secure property values. When deployed with secure properties prefixed with certain non-ASCII characters, the redaction engine may inadequately mask subsequent ASCII secure values. This flaw can lead to inadvertent disclosure of critical information embedded within insecure properties, posing potential risks to data security and privacy.

Affected Version(s)

HCL DevOps Deploy / HCL Launch 7.3 - 7.3.2.20, 8.0 - 8.0.1.15, 8.1 - 8.1.2.8, 8.2 - 8.2.2.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.