CVE-2024-42213
MEDIUMHCL BigFix Compliance - Information Disclosure via Temporary Files
Title source: llmDescription
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.
References (1)
Core 1
Core References
Scores
CVSS v3
5.3
EPSS
0.0033
EPSS Percentile
56.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-531
Status
published
Products (1)
hcltech/bigfix_compliance
2.0.12
Published
May 05, 2025
Tracked Since
Feb 18, 2026