Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

CVE-2023-37507: HCL DevOps Plan Leaks Sensitive Information

CVE-2023-37507 CVE-2023-37507
Summary

An attacker can access sensitive information about your project or organization through HCL DevOps Plan. This can help them launch targeted attacks. To protect yourself, update HCL DevOps Plan to the latest version or apply any available patches.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
hclsoftware devops plan <3.0.05
Original title
An information disclosure vulnerability affects HCL DevOps Plan
Original description
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
Vulnerability type
CWE-497
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026