First published: Thu Mar 27 2025(Updated: )
HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL DevOps Deploy | ||
HCL Launch | ||
>=8.0.0.0<8.0.1.5 | ||
>=8.1.0<8.1.0.1 | ||
>=7.0.0.0<=7.0.5.26 | ||
>=7.1.0.0<7.1.2.22 | ||
>=7.2.0.0<7.2.3.15 | ||
>=7.3.0.0<=7.3.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0273 has a medium severity rating due to the potential exposure of sensitive authentication tokens.
To fix CVE-2025-0273, configure logging settings to prevent sensitive information from being stored in log files.
The risks include unauthorized access to sensitive authentication tokens by local users, leading to potential data breaches.
CVE-2025-0273 affects HCL DevOps Deploy and HCL Launch without specifying particular versions.
Users of HCL DevOps Deploy and HCL Launch are responsible for implementing the fix for CVE-2025-0273.