Impact
This vulnerability in HCL DevOps Deploy / HCL Launch allows an authenticated user to receive API responses that contain sensitive configurations and secrets. The disclosure of such sensitive data could enable attackers to compromise the system. The weakness aligns with CWE-201, an insertion of sensitive information into sent data.
Affected Systems
HCLSoftware’s HCL DevOps Deploy / HCL Launch product is affected. Specific affected versions were not disclosed in the available data, so all released versions of the product should be evaluated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path requires the attacker to authenticate to the application, after which they can trigger the problematic API endpoints and receive the leaked information. Consequently, any authenticated user—either legitimate or compromised—has the potential to abuse this weakness.
OpenCVE Enrichment