HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 17 Jun 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech bigfix Compliance |
|
| CPEs | cpe:2.3:a:hcltech:bigfix_compliance:2.0.11:*:*:*:*:*:*:* | |
| Vendors & Products |
Hcltech
Hcltech bigfix Compliance |
Thu, 07 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 Nov 2024 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel. | |
| Title | HCL BigFix Compliance is affected by a missing secure flag on a cookie | |
| Weaknesses | CWE-614 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published: 2024-11-07T08:58:42.811Z
Updated: 2024-11-07T14:28:08.789Z
Reserved: 2024-03-22T23:57:24.981Z
Link: CVE-2024-30142
Updated: 2024-11-07T14:28:05.421Z
Status : Analyzed
Published: 2024-11-07T09:15:03.907
Modified: 2025-06-17T21:03:34.543
Link: CVE-2024-30142
No data.