HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 07 Nov 2024 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel. | |
Title | HCL BigFix Compliance is affected by a missing secure flag on a cookie | |
Weaknesses | CWE-614 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2024-11-07T14:28:08.789Z
Reserved: 2024-03-22T23:57:24.981Z
Link: CVE-2024-30142

Updated: 2024-11-07T14:28:05.421Z

Status : Awaiting Analysis
Published: 2024-11-07T09:15:03.907
Modified: 2024-11-08T19:01:03.880
Link: CVE-2024-30142

No data.