CVE-2025-62329: HCL DevOps Deploy / HCL Launch is susceptible to an insufficient session expiration vulnerability
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62329?
CVE-2025-62329 is classified as a medium severity vulnerability due to the potential for unauthorized access under certain network conditions.
How do I fix CVE-2025-62329?
To resolve CVE-2025-62329, ensure that your HCL DevOps Deploy and HCL Launch installations are updated to the latest version that addresses this vulnerability.
Which versions of HCL DevOps Deploy are affected by CVE-2025-62329?
CVE-2025-62329 affects all versions of HCL DevOps Deploy prior to the security patch release.
Is CVE-2025-62329 specific to certain network conditions?
Yes, CVE-2025-62329 is particularly relevant in scenarios where network conditions allow for rapid IP changes.
What is the primary risk associated with CVE-2025-62329?
The primary risk of CVE-2025-62329 is the possibility of session reuse from a different IP address, leading to unauthorized access to the application.