CVE-2024-23558: HCL DevOps Deploy / HCL Launch does not invalidate all session authentication cookies after logout
HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23558?
CVE-2024-23558 has been classified as a high severity vulnerability due to the potential for session impersonation.
How do I fix CVE-2024-23558?
To fix CVE-2024-23558, ensure that session invalidation occurs correctly upon user logout in HCL DevOps Deploy and HCL Launch.
Who is affected by CVE-2024-23558?
CVE-2024-23558 affects users of HCL DevOps Deploy and HCL Launch, specifically those who may interact with user sessions.
What are the implications of CVE-2024-23558?
The implications of CVE-2024-23558 include the risk of unauthorized access if an authenticated user can impersonate another user after logout.
Is user data at risk due to CVE-2024-23558?
Yes, user data may be at risk due to CVE-2024-23558, as it allows authenticated users to potentially access or manipulate another user's data.