CVE-2024-42195: HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42195?
CVE-2024-42195 is classified as a medium severity vulnerability due to the potential for HTML injection leading to sensitive information disclosure.
How do I fix CVE-2024-42195?
To fix CVE-2024-42195, HCL recommends updating to the latest version of HCL DevOps Deploy or HCL Launch that addresses this vulnerability.
What type of attack can occur due to CVE-2024-42195?
CVE-2024-42195 can lead to HTML injection attacks, allowing malicious users to embed arbitrary HTML in the Web UI.
Which products are affected by CVE-2024-42195?
The products affected by CVE-2024-42195 are HCL DevOps Deploy and HCL Launch.
What can be compromised due to CVE-2024-42195?
CVE-2024-42195 can potentially lead to the disclosure of sensitive information through the exploitation of HTML injection in the Web UI.