A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 through 3.2.4 and 2.5.0 through 2.5.2 and 2.4.1 and 2.4.0 allows attacker to denial of service via crafted http requests.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-46174 A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 through 3.2.4 and 2.5.0 through 2.5.2 and 2.4.1 and 2.4.0 allows attacker to denial of service via crafted http requests.
Fixes

Solution

Please upgrade to FortiSandbox version 4.4.2 or above Please upgrade to FortiSandbox version 4.2.6 or above Please upgrade to FortiSandbox version 4.0.4 or above


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2024-09-16T20:42:19.766Z

Reserved: 2023-08-30T13:42:39.547Z

Link: CVE-2023-41682

cve-icon Vulnrichment

Updated: 2024-08-02T19:01:35.465Z

cve-icon NVD

Status : Modified

Published: 2023-10-13T15:15:44.123

Modified: 2024-11-21T08:21:28.860

Link: CVE-2023-41682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.