CVE-2024-23558
EUVD-2024-2105315.04.2024, 21:15
HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hcltechsw | hcl_devops_deploy | 8.0.0.0 ≤ 𝑥 < 8.0.1 |
| hcltechsw | hcl_launch | 7.0.0.0 ≤ 𝑥 < 7.0.5.21 |
| hcltechsw | hcl_launch | 7.1.0.0 ≤ 𝑥 < 7.1.2.17 |
| hcltechsw | hcl_launch | 7.2.0.0 ≤ 𝑥 < 7.2.3.10 |
| hcltechsw | hcl_launch | 7.3.0.0 ≤ 𝑥 < 7.3.2.5 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| hcltechsw | hcl_launch | 7.0.0.0 ≤ 𝑥 ≤ 7.0.5.20 | ADP |
| hcltechsw | hcl_launch | 7.1 ≤ 𝑥 ≤ 7.1.2.16 | ADP |
| hcltechsw | hcl_launch | 7.2 ≤ 𝑥 ≤ 7.2.3.9 | ADP |
| hcltechsw | hcl_launch | 7.3 ≤ 𝑥 ≤ 7.3.2.4 | ADP |
| hcltechsw | hcl_devops_deploy | 8.0.0.0 ≤ 𝑥 ≤ 8.0.0.1 | ADP |
Common Weakness Enumeration