CVE Vulnerabilities

CVE-2024-42212

Sensitive Cookie with Improper SameSite Attribute

Published: May 05, 2025 | Modified: Jun 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a users browser into making unintended requests using authenticated sessions.

Weakness

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Affected Software

NameVendorStart VersionEnd Version
Bigfix_complianceHcltech2.0.12 (including)2.0.12 (including)

Potential Mitigations

References