Arbitrary File Download Vulnerability in HCL BigFix Patch Download Plug-ins
CVE-2024-42183
2.5LOW
What is CVE-2024-42183?
The HCL BigFix Patch Download Plug-ins are susceptible to an arbitrary file download vulnerability. This flaw enables a malicious actor to download files from any URL without adequate validation or allowlist controls, potentially compromising system integrity and security. Organizations utilizing these plug-ins must address this issue to prevent unauthorized access to sensitive data. For resolution and further details, refer to HCL's support resources.
Affected Version(s)
BigFix Patch Management Download Plug-ins 1177 and below