HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-28076 HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00051}

epss

{'score': 0.00056}


Tue, 17 Jun 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Compliance
CPEs cpe:2.3:a:hcltech:bigfix_compliance:2.0.11:*:*:*:*:*:*:*
Vendors & Products Hcltech
Hcltech bigfix Compliance

Thu, 07 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 07 Nov 2024 08:30:00 +0000

Type Values Removed Values Added
Description HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.
Title HCL BigFix Compliance is affected by unvalidated redirects and forwards
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2024-11-07T14:28:47.434Z

Reserved: 2024-03-22T23:57:24.980Z

Link: CVE-2024-30140

cve-icon Vulnrichment

Updated: 2024-11-07T14:28:43.732Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-07T09:15:03.480

Modified: 2025-06-17T21:03:05.410

Link: CVE-2024-30140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.