CVE-2024-31493: Medium severity fortinet fortisoar imap connector vulnerability
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31493?
CVE-2024-31493 is classified as a critical severity vulnerability that allows unauthorized access to sensitive information.
How do I fix CVE-2024-31493?
To mitigate CVE-2024-31493, upgrade FortiSOAR to version 7.3.1 or later.
Who is affected by CVE-2024-31493?
CVE-2024-31493 affects FortiSOAR versions 7.3.0, 7.2.2 and below, as well as 7.0.3 and below.
What type of vulnerability is CVE-2024-31493?
CVE-2024-31493 is an improper removal of sensitive information before storage or transfer vulnerability.
What information is exposed in CVE-2024-31493?
CVE-2024-31493 may allow low-privileged authenticated users to read Connector passwords in plain-text via HTTP responses.