An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to obtain sensitive logging informations on the device via crafted HTTP GET requests.
2023-03-07T17:15:12.163
2024-11-21T07:23:03.940
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiproxy | ≤ 7.0.8 | Yes |
Application | fortinet | fortiproxy | ≤ 7.2.2 | Yes |
Operating System | fortinet | fortios | ≤ 6.2.13 | Yes |
Operating System | fortinet | fortios | ≤ 6.4.11 | Yes |
Operating System | fortinet | fortios | ≤ 7.0.9 | Yes |
Operating System | fortinet | fortios | ≤ 7.2.3 | Yes |