CVE-2022-41329: Infoleak
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to obtain sensitive logging informations on the device via crafted HTTP GET requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-41329?
CVE-2022-41329 is an exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiProxy and FortiOS.
How does CVE-2022-41329 affect Fortinet FortiProxy?
CVE-2022-41329 affects Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7.
How does CVE-2022-41329 affect Fortinet FortiOS?
CVE-2022-41329 affects Fortinet FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9.
What is the severity of CVE-2022-41329?
CVE-2022-41329 has a severity score of 5.3 (Medium).
How can I fix CVE-2022-41329?
To fix CVE-2022-41329, update Fortinet FortiProxy to version 7.2.2 or higher and update Fortinet FortiOS to version 7.2.3 or higher.