FG-IR-24-051: Sensitive files disclosure in diagnostic logs download
An exposure of sensitive Information to an unauthorized actor vulnerability [CWE-200] in FortiSandbox may allow an authenticated attacker with at least read-only permission to read sensitive files via HTTP get requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-051?
The severity of FG-IR-24-051 is significant due to the potential for authenticated attackers to access sensitive information.
How do I fix FG-IR-24-051?
To fix FG-IR-24-051, upgrade FortiSandbox to version 4.4.5 or later, or 4.2.7 or later, depending on your current version.
Who is affected by FG-IR-24-051?
Users of Fortinet FortiSandbox versions between 4.0 and 4.4.4, as well as certain versions of 4.2.x and 3.2.x are affected by FG-IR-24-051.
What types of information are exposed in FG-IR-24-051?
FG-IR-24-051 exposes sensitive files that can be accessed by authenticated users with read-only permissions.
What is the nature of the vulnerability in FG-IR-24-051?
The nature of the vulnerability in FG-IR-24-051 is classified as an exposure of sensitive information to unauthorized actors via HTTP GET requests.