CVE-2024-42213CWE-531
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment
Medium · published May 5, 2025
What it is
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.
The record
Technical detail
- CVSS v3.1
- 5.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00295 · 21.8th percentile
- Weakness
- CWE-531 · Inclusion of Sensitive Information in Test Code
- Published
- 2025-05-05T19:00Z
EPSS history
Timeline