CVE-2024-42212

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:bigfix_compliance:2.0.12:*:*:*:*:*:*:*

History

17 Jun 2025, 21:04

Type Values Removed Values Added
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120961 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120961 - Vendor Advisory
Summary
  • (es) HCL BigFix Compliance se ve afectada por un atributo SameSite incorrecto o ausente. Esto puede provocar ataques de Cross-Site Request Forgery (CSRF), donde un sitio malicioso podría engañar al navegador de un usuario para que realice solicitudes no deseadas mediante sesiones autenticadas.
First Time Hcltech
Hcltech bigfix Compliance
CPE cpe:2.3:a:hcltech:bigfix_compliance:2.0.12:*:*:*:*:*:*:*

05 May 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-05 19:15

Updated : 2025-06-17 21:04


NVD link : CVE-2024-42212

Mitre link : CVE-2024-42212

CVE.ORG link : CVE-2024-42212


JSON object : View

Products Affected

hcltech

  • bigfix_compliance
CWE
CWE-1275

Sensitive Cookie with Improper SameSite Attribute