CVE-2024-42196: HCL Launch is susceptible to Insertion of Sensitive Information into Log File vulnerability
Published Dec 6, 2024
·Updated
HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
Affected Software
4 affected components
HCL Launch
Hcltechsw Hcl Launch>=7.0.0.0<7.0.5.25
Hcltechsw Hcl Launch>=7.1.0.0<7.1.2.21
Hcltechsw Hcl Launch>=7.2.0.0<7.2.3.14
Event History
Dec 6, 2024
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42196?
CVE-2024-42196 is classified as a moderate severity vulnerability due to potential exposure of sensitive information.
2
How do I fix CVE-2024-42196?
To mitigate CVE-2024-42196, ensure that log files containing sensitive information are secured and access is restricted.
3
Who is affected by CVE-2024-42196?
CVE-2024-42196 affects all installations of HCL Launch that do not properly secure HTTP request logs.
4
What information is exposed in CVE-2024-42196?
CVE-2024-42196 exposes potentially sensitive information stored in HTTP request logs, which can be read by local users.
5
Is there a way to prevent CVE-2024-42196 in the future?
To prevent CVE-2024-42196, implement robust log management practices and review access controls regularly.