First published: Tue Sep 10 2024(Updated: )
An exposure of sensitive information to an unauthorized actor in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.2 through 3.2.4 and 3.1.5 allows attacker to information disclosure via HTTP get requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSandbox | >=4.4.0<=4.4.4 | |
Fortinet FortiSandbox | >=4.2.0<=4.2.6 | |
Fortinet FortiSandbox | >=4.0 | |
Fortinet FortiSandbox | >=3.2.2<=3.2.4 | |
Fortinet FortiSandbox | =. | |
Fortinet FortiSandbox | >=3.2.2<4.2.7 | |
Fortinet FortiSandbox | >=4.4.0<4.4.5 | |
Fortinet FortiSandbox | =3.1.5 |
Please upgrade to FortiSandbox version 4.4.5 or above Please upgrade to FortiSandbox version 4.2.7 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.