CVE-2024-42213

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/05/2025
Last modified:
17/06/2025

Description

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:bigfix_compliance:2.0.12:*:*:*:*:*:*:*