An exposure of sensitive information to an unauthorized actor in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.2 through 3.2.4 and 3.1.5 allows attacker to information disclosure via HTTP get requests.
2024-09-10T15:15:15.983
2024-09-20T19:48:42.507
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisandbox | < 4.2.7 | Yes |
Application | fortinet | fortisandbox | < 4.4.5 | Yes |
Application | fortinet | fortisandbox | 3.1.5 | Yes |