2025-02-02 03:03:49 +00:00

60 lines
1.8 KiB
JSON

{
"id": "CVE-2024-42184",
"sourceIdentifier": "psirt@hcl.com",
"published": "2025-01-23T03:15:08.727",
"lastModified": "2025-01-23T03:15:08.727",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operator to attempt to download files using the file:// URI scheme."
},
{
"lang": "es",
"value": "Los complementos de BigFix Patch Download se ven afectados por una compatibilidad insegura con el esquema de URI de archivos. Esto podr\u00eda permitir que un operador malintencionado intente descargar archivos utilizando el esquema de URI file://."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "psirt@hcl.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N",
"baseScore": 2.5,
"baseSeverity": "LOW",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 0.8,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "psirt@hcl.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-84"
}
]
}
],
"references": [
{
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118565",
"source": "psirt@hcl.com"
}
]
}