An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19373 | An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests. |
Fixes
Solution
Please upgrade to FortiPortal version 7.4.0 or above Please upgrade to FortiPortal version 7.2.3 or above Please upgrade to FortiPortal version 7.0.8 or above
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-011 |
|
History
Mon, 09 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortiportal |
|
| CPEs | cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiportal:7.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortiportal |
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-01T22:27:36.325Z
Reserved: 2024-01-02T10:15:00.527Z
Link: CVE-2024-21759
Updated: 2024-08-01T22:27:36.325Z
Status : Modified
Published: 2024-07-09T16:15:04.357
Modified: 2024-11-21T08:54:57.347
Link: CVE-2024-21759
No data.
OpenCVE Enrichment
No data.
EUVD