A new vulnerability, CVE-2024-42195, has been identified in HCL DevOps Deploy and HCL Launch, enabling users to embed arbitrary HTML tags in the Web UI, causing potential sensitive information disclosure. HCL Software has urged users to update their systems to safeguard against exploitation. No workarounds or alternative mitigations are currently available.

Harrods customer data stolen from system of 'third-party provider' in latest UK cyber incident – Fox Business
Harrods customer data stolen from system of ‘third-party provider’ in latest UK cyber incident Fox Business