CVE Vulnerabilities

CVE-2024-42212

Sensitive Cookie with Improper SameSite Attribute

Published: May 05, 2025 | Modified: Jun 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a users browser into making unintended requests using authenticated sessions.

Weakness

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Affected Software

Name Vendor Start Version End Version
Bigfix_compliance Hcltech 2.0.12 (including) 2.0.12 (including)

Potential Mitigations

References