CVE-2024-23550: HCL DevOps Deploy / HCL Launch (UCD) may be vulnerable to sensitive information disclosure
Published Feb 3, 2024
·Updated
HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.
Affected Software
5 affected components
Hcltechsw Hcl Devops Deploy=8.0.0.0
Hcltechsw Hcl Launch>=7.0.0.0<7.0.5.20
Hcltechsw Hcl Launch>=7.1.0.0<7.1.2.16
Hcltechsw Hcl Launch>=7.2.0.0<7.2.3.9
Hcltechsw Hcl Launch>=7.3.0.0<7.3.2.4
Event History
Feb 3, 2024
CVE Published
via MITRE·05:32 AM
Data Sourced
via MITRE·05:32 AM
DescriptionSeverity
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23550?
CVE-2024-23550 is considered to have a medium severity due to the potential disclosure of sensitive user information.
2
How do I fix CVE-2024-23550?
To fix CVE-2024-23550, it is recommended to update HCL DevOps Deploy and HCL Launch to the latest patched versions.
3
Which versions of HCL software are affected by CVE-2024-23550?
CVE-2024-23550 affects HCL DevOps Deploy version 8.0.0.0 and multiple versions of HCL Launch from 7.0.0.0 to 7.3.2.4.
4
What kind of information could be disclosed by CVE-2024-23550?
CVE-2024-23550 could disclose sensitive user information during the installation of the Windows agent.
5
Is there a workaround for CVE-2024-23550?
Currently, there is no official workaround for CVE-2024-23550, and the best approach is to apply the available updates.