CVE-2024-30142 - HCL BigFix Compliance Cookie Insecure Storage Vulnerability

2 weeks ago 8
ARTICLE AD BOX
CVE ID : CVE-2024-30142
Published : Nov. 7, 2024, 9:15 a.m. | 24 minutes ago
Description : HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.
Severity: 3.8 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article