CVE-2024-23560: HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom type
Published Apr 15, 2024
·Updated
HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.
Affected Software
2 affected components
HCL DevOps Deploy
HCL Launch
Event History
Apr 15, 2024
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
DescriptionSeverity
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-23560?
CVE-2024-23560 is classified as a vulnerability that poses a potential risk due to incomplete revocation of permissions.
2
How do I fix CVE-2024-23560?
To fix CVE-2024-23560, ensure that the custom security resource types are properly managed and permissions are fully revoked upon deletion.
3
Which products are affected by CVE-2024-23560?
CVE-2024-23560 affects both HCL DevOps Deploy and HCL Launch.
4
What can happen if CVE-2024-23560 is exploited?
Exploitation of CVE-2024-23560 may lead to unauthorized access due to residual permissions not being revoked.
5
Is there a patch available for CVE-2024-23560?
Details regarding a patch for CVE-2024-23560 can be found in the official HCL support documentation.