PT-2024-23212 · Hcl · Hcl Bigfix Compliance

Published

2024-11-07

·

Updated

2024-11-08

·

CVE-2024-30142

CVSS v3.1

3.8

Low

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions HCL BigFix Compliance (affected versions not specified)
Description The issue is related to a missing secure flag on a cookie in HCL BigFix Compliance. This missing flag allows cookies to be stolen by an attacker using XSS, resulting in unauthorized access. Additionally, session cookies could be transferred over an unencrypted channel.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-30142

Affected Products

Hcl Bigfix Compliance