First published: Mon Oct 31 2022(Updated: )
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Hcl Launch Container Image | >=7.0.0.0<=7.0.52 | |
Hcltech Hcl Launch Container Image | >=7.1.0.0<7.1.0.1 | |
Hcltech Hcl Launch Container Image | >=7.2.0.0<=7.2.3.0 | |
Hcltech Hcl Launch Container Image | =7.1.0.1 | |
Hcltech Hcl Launch Container Image | =7.1.0.1-ifix01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-27784.
The severity of CVE-2021-27784 is high, with a CVSS score of 7.5.
CVE-2021-27784 affects HCL Launch Container images versions 7.0.0.0 to 7.0.52, 7.1.0.0 to 7.1.0.1, and 7.2.0.0 to 7.2.3.0.
CVE-2021-27784 allows attackers to potentially compromise the confidentiality and integrity of HTTPS communication and the encryption of the database.
To fix CVE-2021-27784, follow the directions and use the provided tools from HCL to replace the non-unique keys and certificates.