IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
| Software | From | Fixed in |
|---|---|---|
| ibm / devops_deploy | 8.0.0.0 | 8.0.1.3.x |
| ibm / urbancode_deploy | 7.2 | 7.2.3.13.x |
| ibm / urbancode_deploy | 7.3 | 7.3.2.8.x |