First published: Thu Dec 05 2024(Updated: )
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL DevOps Deploy | ||
HCL Launch | ||
HCL DevOps Deploy | >=8.0.0.0<8.0.1.4 | |
HCL Launch | >=7.0.0.0<7.0.5.25 | |
HCL Launch | >=7.1.0.0<7.1.2.21 | |
HCL Launch | >=7.2.0.0<7.2.3.14 | |
HCL Launch | >=7.3.0.0<7.3.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42195 is classified as a medium severity vulnerability due to the potential for HTML injection leading to sensitive information disclosure.
To fix CVE-2024-42195, HCL recommends updating to the latest version of HCL DevOps Deploy or HCL Launch that addresses this vulnerability.
CVE-2024-42195 can lead to HTML injection attacks, allowing malicious users to embed arbitrary HTML in the Web UI.
The products affected by CVE-2024-42195 are HCL DevOps Deploy and HCL Launch.
CVE-2024-42195 can potentially lead to the disclosure of sensitive information through the exploitation of HTML injection in the Web UI.