First published: Wed Apr 02 2025(Updated: )
HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL DevOps Deploy | ||
HCL Launch | ||
HCL DevOps Deploy | >=8.0.0.0<8.0.1.6 | |
HCL DevOps Deploy | >=8.1.0<8.1.1 | |
HCL Launch | >=7.1.0.0<7.1.2.23 | |
HCL Launch | >=7.2.0.0<7.2.3.16 | |
HCL Launch | >=7.3.0.0<7.3.2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0257 is classified as a high severity vulnerability due to potential unauthorized access and data exposure.
To fix CVE-2025-0257, ensure that proper authentication mechanisms are implemented in the Agent Relay service.
CVE-2025-0257 affects HCL DevOps Deploy and HCL Launch.
CVE-2025-0257 is an authentication vulnerability that allows unauthorized access to services.
The consequences of CVE-2025-0257 may include unauthorized access to other services and the potential exposure of sensitive data.