An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-011 |
History
Mon, 09 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fortinet
Fortinet fortiportal |
|
CPEs | cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiportal:7.2.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Fortinet
Fortinet fortiportal |
MITRE
Status: PUBLISHED
Assigner: fortinet
Published: 2024-07-09T15:33:31.028Z
Updated: 2024-08-01T22:27:36.325Z
Reserved: 2024-01-02T10:15:00.527Z
Link: CVE-2024-21759
Vulnrichment
Updated: 2024-08-01T22:27:36.325Z
NVD
Status : Modified
Published: 2024-07-09T16:15:04.357
Modified: 2024-11-21T08:54:57.347
Link: CVE-2024-21759
Redhat
No data.