FG-IR-24-268: Insertion of sensitive information into REST API logs
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS, FortiProxy, FortiPAM and FortiSRA may allow a read-only administrator to retrieve API tokens of other administrators via observing REST API logs, if REST API logging is enabled (non-default configuration).
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-268?
The severity of FG-IR-24-268 is categorized as a significant risk due to unauthorized access to sensitive information.
How do I fix FG-IR-24-268?
To fix FG-IR-24-268, upgrade to FortiOS versions 7.4.4 or 7.2.8, depending on your current version.
What products are affected by FG-IR-24-268?
FG-IR-24-268 affects FortiOS, FortiProxy, FortiPAM, and FortiSRA across specific versions.
Can FG-IR-24-268 be exploited remotely?
Yes, FG-IR-24-268 can potentially be exploited remotely by a read-only administrator who has access to the REST API logs.
What should be done if I cannot upgrade to a fixed version for FG-IR-24-268?
If upgrading is not possible, consider disabling REST API logging to mitigate the risk associated with FG-IR-24-268.