Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HCL Launch is susceptible to an HTML injection vulnerability
Vulnerability Description
HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
HCL Technologies HCL Launch 安全漏洞
Vulnerability Description
HCL Technologies HCL Launch是美国HCL Technologies公司的一款多功能的企业级持续交付自动化软件。用于处理 DevOps 中最复杂的部署流程。 HCL Launch存在安全漏洞,该漏洞源于允许攻击者在Web UI中嵌入任意HTML代码,从而导致敏感信息泄露。受影响的产品和版本:HCL Launch 7.1至7.1.2.14版本,7.2至7.2.3.7版本,7.3至7.3.2.2版本。
CVSS Information
N/A
Vulnerability Type
N/A