CVE-2025-0272: HCL DevOps Deploy / HCL Launch is susceptible to an HTML injection vulnerability
Published Apr 3, 2025
·Updated
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Affected Software
8 affected components
HCL DevOps Deploy
HCL Launch
Hcltechsw Hcl Devops Deploy>=8.0.0.0<8.0.1.5
Hcltechsw Hcl Devops Deploy>=8.1.0<8.1.0.1
Hcltechsw Hcl Launch>=7.0.0.0<=7.0.5.26
Hcltechsw Hcl Launch>=7.1.0.0<7.1.2.22
Hcltechsw Hcl Launch>=7.2.0.0<7.2.3.15
Hcltechsw Hcl Launch>=7.3.0.0<=7.3.2.9
Event History
Apr 3, 2025
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-0272?
CVE-2025-0272 has a moderate severity level due to its potential for HTML injection leading to sensitive information disclosure.
2
How do I fix CVE-2025-0272?
To fix CVE-2025-0272, ensure that all input is properly sanitized and validated to prevent HTML injection.
3
Which products are affected by CVE-2025-0272?
CVE-2025-0272 affects HCL DevOps Deploy and HCL Launch.
4
What is the impact of CVE-2025-0272?
The impact of CVE-2025-0272 includes the risk of sensitive information disclosure through the Web UI.
5
Is there a patch available for CVE-2025-0272?
Currently, specific patch details for CVE-2025-0272 have not been provided, so check with HCL support for updates.