Executive brief
HCL DevOps Deploy and HCL Launch are deployment automation tools used by organizations to manage application releases and infrastructure changes. A flaw in the redaction system can leak sensitive credentials and configuration data when deployments contain specially crafted secure properties, potentially exposing passwords and API keys to unauthorized users.
Technical details
This is an information disclosure vulnerability in the redaction engine of HCL DevOps Deploy/Launch. When a deployment is configured with a secure (redacted) property that begins with certain non-ASCII characters, the redaction mechanism fails to mask subsequent ASCII-based secure values that are embedded within insecure properties. This allows an attacker with access to deployment configurations or logs to recover sensitive plaintext values that should have been redacted. The vulnerability requires access to view deployment configurations; there is no network or authentication bypass component. A patch is available from HCL Software.
Affected products
- HCL DevOps Deploy
- HCL Launch
Timeline
- 2026-09-17: disclosed