Executive brief
HCL DevOps Plan, a tool used for managing software development lifecycles and project planning, is affected by a security flaw that leaks sensitive system information. An unauthorized user could view internal details about the application's environment, which could be used to plan more sophisticated attacks against the organization. This vulnerability could potentially lead to a broader compromise of the development environment if not addressed.
Technical details
HCL DevOps Plan versions prior to 3.0.05 are vulnerable to an information disclosure flaw categorized as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). The vulnerability allows a remote, unauthenticated attacker to access sensitive system-level information via the network. This exposure does not directly allow for data modification or service disruption but provides reconnaissance data that facilitates targeted secondary attacks. The issue is resolved in version 3.0.05.
Affected products
- HCL Software DevOps Plan < 3.0.05
Timeline
- 2026-07-21: advisory
- 2026-07-21: disclosed