Description
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39450 | BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access. |
References
History
Thu, 23 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access. | |
| Title | HCL BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2025-01-23T14:51:45.463Z
Reserved: 2024-07-29T21:32:05.158Z
Link: CVE-2024-42185
Updated: 2025-01-23T14:51:40.319Z
Status : Received
Published: 2025-01-23T03:15:08.860
Modified: 2025-01-23T03:15:08.860
Link: CVE-2024-42185
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD