CVE-2024-42212
05.05.2025, 19:15
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.Enginsight
Vendor | Product | Version |
---|---|---|
hcltech | bigfix_compliance | 2.0.12 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration