Executive brief
HCL DevOps Plan, a tool used for managing software development lifecycles, is affected by a security flaw that could allow an attacker to run malicious scripts in a user's browser. This typically occurs if a user visits a specially crafted link while certain browser security weaknesses are present. Successful exploitation could lead to unauthorized actions being performed on behalf of the user or the theft of session information.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in HCL DevOps Plan versions prior to 3.0.05. The flaw stems from improper neutralization of input during web page generation (CWE-79). An attacker can exploit this by tricking a user into interacting with a malicious link or page, potentially leading to the execution of arbitrary JavaScript in the context of the victim's session. The vulnerability has a high attack complexity and requires user interaction, as noted in the CVSS 4.0 vector. Users are advised to upgrade to version 3.0.05 or later to mitigate this risk.
Affected products
- HCL Software DevOps Plan < 3.0.05
Timeline
- 2026-07-21: disclosed: Initial advisory publication
- 2026-07-21: advisory: NVD record published