Security Advisory

CVE-2024-42212

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-05-05 18:40:57
Last updated 2025-05-05 19:01:02
Assigner HCL
CVSS score 5.4
State PUBLISHED

Description

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.