Lucene search

K
vulnrichmentHCLVULNRICHMENT:CVE-2024-23561
HistoryApr 15, 2024 - 8:20 p.m.

CVE-2024-23561 HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability

2024-04-1520:20:51
HCL
github.com
2
hcl devops deploy
hcl launch
sensitive information disclosure
insufficient obfuscation

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.4

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

CNA Affected

[
  {
    "vendor": "HCL Software",
    "product": "DevOps Deploy / Launch",
    "versions": [
      {
        "status": "affected",
        "version": "7.1 - 7.1.2.16,  7.2 - 7.2.3.9,  7.3 - 7.3.2.4, 8.0 - 8.0.0.1"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.4

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-23561