Exposure of Sensitive Information Through Metadata
CVE-2025-31959
Summary
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
- LOW
- NETWORK
- NONE
- UNCHANGED
- REQUIRED
- LOW
- LOW
- NONE
CWE-1230 - Exposure of Sensitive Information Through Metadata
The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.
References
Advisory Timeline
- Published