Impact
The vulnerability lies in the redaction engine that improperly removes sensitive information when processing secure property values. If a deployment configuration contains a secure property starting with certain non-ASCII characters, the engine may fail to mask ASCII secure values embedded inside insecure properties, leading to exposure of confidential data. This weakness is classified as CWE-212, an improper removal of sensitive information before storage or transfer.
Affected Systems
The affected product is HCLSoftware HCL DevOps Deploy / HCL Launch. No specific versions are indicated in the available data, so it is recommended to verify all deployed instances.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk. The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack path involves an attacker modifying a deployment configuration to insert a secure property that begins with non-ASCII characters; this can then trigger the redaction failure and disclose sensitive values. No publicly available exploit is known, but the combination of a remote configuration ability and the flaw means that any user with deployment privileges could potentially exploit this weakness.
OpenCVE Enrichment