CVE-2025-62330: HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information
HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related data via passive monitoring or man-in-the-middle attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62330?
The severity of CVE-2025-62330 is classified as critical due to the exposure of sensitive information over unencrypted HTTP.
How do I fix CVE-2025-62330?
To fix CVE-2025-62330, ensure that all network communications are redirected from HTTP to HTTPS and configure your server to enforce secure connections.
What types of information are at risk with CVE-2025-62330?
CVE-2025-62330 puts user credentials and session-related data at risk due to cleartext transmission.
Who is affected by CVE-2025-62330?
Users and administrators of HCL DevOps Deploy are affected by CVE-2025-62330 if they have not implemented HTTPS.
Can CVE-2025-62330 lead to unauthorized access?
Yes, CVE-2025-62330 can lead to unauthorized access as attackers can intercept user credentials transmitted over unencrypted HTTP.