Cache Poisoning Vulnerability in HCL BigFix SaaS Authentication Service
CVE-2025-52621
5.3MEDIUM
What is CVE-2025-52621?
The HCL BigFix SaaS Authentication Service has a vulnerability that allows for cache poisoning attacks due to the inclusion of the Origin header in its HTTP responses. This can potentially lead to the exploitation of an unvalidated reflection of the header value, thereby compromising the integrity of cached content and enabling attackers to serve malicious responses.
Affected Version(s)
BigFix SaaS Remediate < 8.1.14