CVE-2024-30141

MEDIUM

HCL BigFix Compliance - Info Disclosure

Title source: llm
STIX 2.1

Description

HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data.

Scores

CVSS v3 4.7
EPSS 0.0013
EPSS Percentile 32.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
hcltech/bigfix_compliance 2.0.11
Published Nov 07, 2024
Tracked Since Feb 18, 2026