CVE-2024-42212
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-1275
- Published
- 2025-05-05
- Last modified
- 2026-03-13
Affected products
- HCL Software HCL BigFix Compliance
Weakness type
Related vulnerabilities
- CVE-2026-81888 — @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
- CVE-2026-73847 — Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
- CVE-2026-55688 — AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
- CVE-2026-8409 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete
- CVE-2026-8410 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete
- CVE-2026-8411 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete
- CVE-2026-8412 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache
- CVE-2026-8413 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design