CVE-2024-23560
MEDIUMDescription
HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.
Is your site exposed to CVE-2024-23560?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hcltechsw | hcl_devops_deploy |
| hcltechsw | hcl_launch |
| hcltechsw | hcl_launch |
| hcltechsw | hcl_launch |
| hcltechsw | hcl_launch |
References
Frequently Asked Questions
What is CVE-2024-23560? +
How severe is CVE-2024-23560? +
What products are affected by CVE-2024-23560? +
How do I check if I'm vulnerable to CVE-2024-23560? +
Related Vulnerabilities
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of …
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and …
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via …
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content …
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When …