CVE-2024-42195

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*

History

21 Apr 2025, 16:50

Type Values Removed Values Added
CWE CWE-79
Summary
  • (es) HCL DevOps Deploy / HCL Launch es vulnerable a la inyección de HTML. Esta vulnerabilidad puede permitir que un usuario incorpore etiquetas HTML arbitrarias en la interfaz de usuario web, lo que podría provocar la divulgación de información confidencial.
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0117908 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0117908 - Vendor Advisory
First Time Hcltechsw
Hcltechsw hcl Devops Deploy
Hcltechsw hcl Launch
CPE cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*

05 Dec 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-05 05:15

Updated : 2025-04-21 16:50


NVD link : CVE-2024-42195

Mitre link : CVE-2024-42195

CVE.ORG link : CVE-2024-42195


JSON object : View

Products Affected

hcltechsw

  • hcl_launch
  • hcl_devops_deploy
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')