An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to obtain sensitive logging informations on the device via crafted HTTP GET requests.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-44536 An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to obtain sensitive logging informations on the device via crafted HTTP GET requests.
Fixes

Solution

Please upgrade to FortiProxy version 7.2.2 or above Please upgrade to FortiProxy version 7.0.8 or above Please upgrade to FortiOS version 7.2.4 or above Please upgrade to FortiOS version 7.0.10 or above Please upgrade to FortiOS version 6.4.11 or above


Workaround

No workaround given by the vendor.

References
History

Wed, 23 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2024-10-23T14:31:07.124Z

Reserved: 2022-09-23T15:07:35.781Z

Link: CVE-2022-41329

cve-icon Vulnrichment

Updated: 2024-08-03T12:42:46.191Z

cve-icon NVD

Status : Modified

Published: 2023-03-07T17:15:12.163

Modified: 2024-11-21T07:23:03.940

Link: CVE-2022-41329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.