A new vulnerability, CVE-2024-42195, has been identified in HCL DevOps Deploy and HCL Launch, enabling users to embed arbitrary HTML tags in the Web UI, causing potential sensitive information disclosure. HCL Software has urged users to update their systems to safeguard against exploitation. No workarounds or alternative mitigations are currently available.

GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition
GitLab has released emergency security updates for both Community Edition (CE) and Enterprise Edition (EE), addressing multiple Duo AI, denial‑of‑service, and authorization flaws in recent


