Описание
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 8.0.0.0 (включая) до 8.0.1.11 (исключая)Версия от 8.1.0 (включая) до 8.1.2.4 (исключая)Версия от 7.3.0.0 (включая) до 7.3.2.16 (исключая)
Одно из
cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00058
Низкий
5 Medium
CVSS3
5.6 Medium
CVSS3
Дефекты
CWE-613
Связанные уязвимости
CVSS3: 5
github
около 2 месяцев назад
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.
EPSS
Процентиль: 18%
0.00058
Низкий
5 Medium
CVSS3
5.6 Medium
CVSS3
Дефекты
CWE-613