Low severity3.8NVD Advisory· Published Nov 7, 2024· Updated Jun 17, 2026
CVE-2024-30142
CVE-2024-30142
Description
HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.
Affected products
3- cpe:2.3:a:hcltech:bigfix_compliance:2.0.11:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 2.0.11
Patches
Vulnerability mechanics
References
1- support.hcl-software.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.