CVE-2024-42213
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.29%
- CWE
- CWE-531
- Published
- 2025-05-05
- Last modified
- 2026-03-13
Affected products
- HCL Software HCL BigFix Compliance
Weakness type
Related vulnerabilities
- CVE-2025-43717 — In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably...