Description
BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious operator to download files from arbitrary URLs without any proper validation or allowlist controls.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 23 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious operator to download files from arbitrary URLs without any proper validation or allowlist controls. | |
| Title | HCL BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability | |
| Weaknesses | CWE-494 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2025-01-23T14:53:30.106Z
Reserved: 2024-07-29T21:32:05.157Z
Link: CVE-2024-42183
Updated: 2025-01-23T14:53:24.285Z
Status : Deferred
Published: 2025-01-23T02:15:35.933
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-42183
No data.
OpenCVE Enrichment
No data.
Weaknesses