HCL BigFix SaaS Authentication Service is vulnerable to...
Moderate severity
Unreviewed
Published
Aug 16, 2025
to the GitHub Advisory Database
•
Updated Aug 16, 2025
Description
Published by the National Vulnerability Database
Aug 15, 2025
Published to the GitHub Advisory Database
Aug 16, 2025
Last updated
Aug 16, 2025
HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning. The BigFix SaaS's HTTP responses were observed to include the Origin header. Its presence alongside an unvalidated reflection of the Origin header value introduces a potential for cache poisoning.
References