First published: Mon Mar 24 2025(Updated: )
HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL DevOps Deploy | ||
HCL Launch | ||
HCL DevOps Deploy | >=8.0.0.0<8.0.1.5 | |
HCL DevOps Deploy | =8.1.0 | |
HCL Launch | >=7.0.0.0<7.0.5.26 | |
HCL Launch | >=7.1.0.0<7.1.2.22 | |
HCL Launch | >=7.2.0.0<7.2.3.15 | |
HCL Launch | >=7.3.0.0<7.3.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0256 has a medium severity rating based on its potential impact on sensitive user information.
To fix CVE-2025-0256, ensure that proper authorization checks are implemented in the affected HCL DevOps Deploy and HCL Launch applications.
CVE-2025-0256 affects authenticated users of HCL DevOps Deploy and HCL Launch who can access sensitive information about other users.
Systems running HCL DevOps Deploy and HCL Launch are vulnerable to CVE-2025-0256 due to the missing authorization for certain functions.
Currently, the best temporary workaround for CVE-2025-0256 is to limit user access rights until a proper fix is applied.