CVE-2024-31490: Sensitive files disclosure in diagnostic logs download
An exposure of sensitive Information to an unauthorized actor vulnerability [CWE-200] in FortiSandbox may allow an authenticated attacker with at least read-only permission to read sensitive files via HTTP get requests.
Other sources
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2.2 through 3.2.4, FortiSandbox 3.1.5 allows attacker to information disclosure via HTTP get requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31490?
CVE-2024-31490 has a severity rating that indicates a medium risk due to exposure of sensitive information.
How do I fix CVE-2024-31490?
To fix CVE-2024-31490, update Fortinet FortiSandbox to version 4.4.5 or above, 4.2.7 or above, or apply other relevant patches.
What versions of FortiSandbox are affected by CVE-2024-31490?
CVE-2024-31490 affects FortiSandbox versions from 4.4.0 through 4.4.4, 4.2.0 through 4.2.6, 4.0.0 through 4.0.5, 3.2.2 through 3.2.4, and 3.1.5.
What type of attack is associated with CVE-2024-31490?
CVE-2024-31490 allows an unauthorized actor to perform information disclosure via HTTP GET requests.
Is there a workaround for CVE-2024-31490?
There is no documented workaround for CVE-2024-31490, so upgrading to a non-vulnerable version is recommended.