First published: Thu Apr 03 2025(Updated: )
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL DevOps Deploy | ||
HCL Launch | ||
HCL DevOps Deploy | >=8.0.0.0<8.0.1.5 | |
HCL DevOps Deploy | >=8.1.0<8.1.0.1 | |
HCL Launch | >=7.0.0.0<=7.0.5.26 | |
HCL Launch | >=7.1.0.0<7.1.2.22 | |
HCL Launch | >=7.2.0.0<7.2.3.15 | |
HCL Launch | >=7.3.0.0<=7.3.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0272 has a moderate severity level due to its potential for HTML injection leading to sensitive information disclosure.
To fix CVE-2025-0272, ensure that all input is properly sanitized and validated to prevent HTML injection.
CVE-2025-0272 affects HCL DevOps Deploy and HCL Launch.
The impact of CVE-2025-0272 includes the risk of sensitive information disclosure through the Web UI.
Currently, specific patch details for CVE-2025-0272 have not been provided, so check with HCL support for updates.