ZeroHour

CVE-2024-42213

CVSS 3.1
5.3 medium
EPSS
<1%p22
Published
()
Modified
Description

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.

Vendors
hcltech
Products
bigfix compliance
Weakness
CWE-531
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.