FG-IR-23-454: Arbitrary file delete on endpoint
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox may allow an authenticated attacker with at least read-only permission to delete arbitrary files via crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-454?
The severity of FG-IR-23-454 is moderate due to its potential impact allowing authenticated attackers to delete arbitrary files.
How do I fix FG-IR-23-454?
To fix FG-IR-23-454, upgrade FortiSandbox to version 4.4.4 or later, 4.2.7 or later, or 4.0.5 or later depending on the current version.
What causes FG-IR-23-454?
FG-IR-23-454 is caused by an improper limitation of a pathname allowing path traversal attacks.
Who is affected by FG-IR-23-454?
Authenticated users with at least read-only permissions on affected versions of FortiSandbox are vulnerable to FG-IR-23-454.
What types of FortiSandbox versions are vulnerable to FG-IR-23-454?
Versions between 4.4.0 and 4.4.3, 4.2.0 and 4.2.6, and 4.0.0 and 4.0.4 of FortiSandbox are vulnerable to FG-IR-23-454.