Lucene search

K
cveHCLCVE-2024-23561
HistoryApr 15, 2024 - 9:15 p.m.

CVE-2024-23561

2024-04-1521:15:07
HCL
web.nvd.nist.gov
30
hcl deployment
sensitive information
disclosure
vulnerability
obfuscation

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

9.0%

HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "DevOps Deploy / Launch",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "7.1 - 7.1.2.16,  7.2 - 7.2.3.9,  7.3 - 7.3.2.4, 8.0 - 8.0.0.1"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2024-23561