Unrated severityNVD Advisory· Published Apr 15, 2024· Updated Nov 1, 2024
HCL DevOps Deploy / HCL Launch does not invalidate all session authentication cookies after logout
CVE-2024-23558
Description
HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Affected products
1- Range: 7.0 - 7.0.5.20, 7.1 - 7.1.2.16, 7.2 - 7.2.3.9, 7.3 - 7.3.2.4, 8.0 - 8.0.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.