CVE-2026-67071
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside insecure properties.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCLSoftware | HCL DevOps Deploy / HCL Launch | 7.3 - 7.3.2.20, 8.0 - 8.0.1.15, 8.1 - 8.1.2.8, 8.2 - 8.2.2.1 | affected |
Weaknesses
- CWE-212: CWE-212 Improper removal of sensitive information before storage or transfer
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.