SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-30142

HCL BigFix Compliance is affected by a missing secure flag on a cookie.

LOW 3.8EPSS 0.10%

Does this matter?

Lower severity and a low EPSS score (0.10%). Track it; it rarely justifies an emergency change on its own.

Description

HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.

CVSS 3.1
3.8 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
EPSS
0.10% probability · 1th percentile
CISA KEV
Not listed
Weakness
CWE-614
Affected
hcltech/bigfix compliance
Source
psirt@hcl.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.