CVE-2022-29062: Path Traversal
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29062?
CVE-2022-29062 is classified as a high-severity vulnerability due to its potential to allow authenticated attackers to write to the filesystem.
How do I fix CVE-2022-29062?
To mitigate CVE-2022-29062, upgrade Fortinet FortiSOAR to version 7.2.1 or later.
What are the vulnerabilities associated with CVE-2022-29062?
CVE-2022-29062 contains multiple relative path traversal vulnerabilities that may lead to arbitrary file writing.
Who is affected by CVE-2022-29062?
Users of Fortinet FortiSOAR versions 7.0.0 to 7.0.3 and version 7.2.0 are affected by CVE-2022-29062.
What type of attack can exploit CVE-2022-29062?
CVE-2022-29062 can be exploited by authenticated attackers through crafted HTTP requests to gain unauthorized file system access.