First published: Tue Jan 16 2024(Updated: )
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL BigFix Bare Metal Server WebUI | <311.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37522 has a medium severity rating due to the potential for cross-site scripting attacks.
To fix CVE-2023-37522, upgrade HCL BigFix Bare OSD Metal Server WebUI to version 311.28 or later.
The risks associated with CVE-2023-37522 include unauthorized script execution that can compromise user sessions.
Versions 311.19 and lower of HCL BigFix Bare OSD Metal Server WebUI are affected by CVE-2023-37522.
There is no official workaround for CVE-2023-37522; upgrading to a secure version is the recommended action.