PT-2023-21482 · Hcl · Hcl Bigfix Osd Bare Metal Server

CVE-2023-28016

·

Publicado

2023-06-22

·

Atualizado

2023-07-03

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HCL BigFix OSD Bare Metal Server versions 311.12 or lower
Description The issue allows an attacker to supply invalid input, causing the server to perform a redirect to an attacker-controlled domain. This is achieved through a Host Header Injection.
Recommendations For HCL BigFix OSD Bare Metal Server versions 311.12 or lower, update to a version higher than 311.12 to resolve the issue. As a temporary workaround, consider restricting access to the server to minimize the risk of exploitation.

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28016

Produtos afetados

Hcl Bigfix Osd Bare Metal Server