nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-42184 CVE-2024-42184
LOW
HCL BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme
Record summary
CVE-2024-42184 has a selected CVSS score of 2.5 (low).
Description
BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operator to attempt to download files using the file:// URI scheme.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
BigFix Patch Management Download Plug-insBrowse HCL Software / BigFix Patch Management Download Plug-insDefault status: unaffected | CVE List | 1177 and below | affected |
References
2support.hcl-software.com
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118565