Описание
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:hcltech:bigfix_compliance:2.0.12:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00044
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-1275
Связанные уязвимости
CVSS3: 5.4
github
9 месяцев назад
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
EPSS
Процентиль: 13%
0.00044
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-1275