CVE-2025-0273: HCL DevOps Deploy / HCL Launch is susceptible to Insertion of Sensitive Information into Log File vulnerability
Published Mar 27, 2025
·Updated
HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.
Affected Software
8 affected components
HCL DevOps Deploy
HCL Launch
Hcltechsw Hcl Devops Deploy>=8.0.0.0<8.0.1.5
Hcltechsw Hcl Devops Deploy>=8.1.0<8.1.0.1
Hcltechsw Hcl Launch>=7.0.0.0<=7.0.5.26
Hcltechsw Hcl Launch>=7.1.0.0<7.1.2.22
Hcltechsw Hcl Launch>=7.2.0.0<7.2.3.15
Hcltechsw Hcl Launch>=7.3.0.0<=7.3.2.9
Event History
Mar 27, 2025
CVE Published
via MITRE·05:03 AM
Data Sourced
via MITRE·05:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0273?
CVE-2025-0273 has a medium severity rating due to the potential exposure of sensitive authentication tokens.
2
How do I fix CVE-2025-0273?
To fix CVE-2025-0273, configure logging settings to prevent sensitive information from being stored in log files.
3
What are the potential risks of CVE-2025-0273?
The risks include unauthorized access to sensitive authentication tokens by local users, leading to potential data breaches.
4
Which software versions are affected by CVE-2025-0273?
CVE-2025-0273 affects HCL DevOps Deploy and HCL Launch without specifying particular versions.
5
Who is responsible for addressing CVE-2025-0273?
Users of HCL DevOps Deploy and HCL Launch are responsible for implementing the fix for CVE-2025-0273.