CVE-2024-42213CWE-531

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment

Medium · published May 5, 2025

CVSS v3.1
5.3
EPSS
0%
Percentile
21.8
In the wild
Unconfirmed
What it is

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00295 · 21.8th percentile
Weakness
CWE-531 · Inclusion of Sensitive Information in Test Code
Published
2025-05-05T19:00Z
EPSS history
Timeline
  • 05 MAY 19:00Z
    HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment
    cvelistv5