HCL DevOps Deploy
cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*
- >= 8.1, <= 8.1.2.3
A vulnerability exists in HCL DevOps Deploy versions 8.1.2.0 through 8.1.2.3, where a user with LLM configuration privileges may recover credentials saved for authenticated LLM queries. This issue arises from inadequate protection of these credentials, allowing for potential unauthorized access or misuse.
Exploitation of this vulnerability could lead to the unauthorized recovery of sensitive credentials, which could then be used to perform authenticated LLM queries, potentially compromising the integrity of the application's data handling or decision-making processes.
Users are advised to upgrade to version 8.1.2.4, 8.2.0.0, or later. These versions are available through the My HCLSoftware Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.