CVE-2025-0256: HCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosure
HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0256?
CVE-2025-0256 has a medium severity rating based on its potential impact on sensitive user information.
How do I fix CVE-2025-0256?
To fix CVE-2025-0256, ensure that proper authorization checks are implemented in the affected HCL DevOps Deploy and HCL Launch applications.
Who is affected by CVE-2025-0256?
CVE-2025-0256 affects authenticated users of HCL DevOps Deploy and HCL Launch who can access sensitive information about other users.
What systems are vulnerable to CVE-2025-0256?
Systems running HCL DevOps Deploy and HCL Launch are vulnerable to CVE-2025-0256 due to the missing authorization for certain functions.
Is there a workaround for CVE-2025-0256?
Currently, the best temporary workaround for CVE-2025-0256 is to limit user access rights until a proper fix is applied.