FG-IR-24-282: File-Filter Bypass in Explicit Web Proxy Policy
An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in FortiOS, FortiProxy and FortiSASE may allow a remote unauthenticated attacker to bypass the file filter via crafted HTTP header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-282?
The severity of FG-IR-24-282 is classified as critical due to the potential for remote unauthenticated exploitation.
How do I fix FG-IR-24-282?
To fix FG-IR-24-282, upgrade FortiOS, FortiProxy, or FortiSASE to the recommended versions specified in the advisory.
Which products are affected by FG-IR-24-282?
FG-IR-24-282 affects multiple versions of FortiOS and FortiProxy, specifically versions below 7.6.1 and 7.4.6 respectively.
Can FG-IR-24-282 be exploited without authentication?
Yes, FG-IR-24-282 can be exploited by remote unauthenticated attackers through specially crafted HTTP headers.
What is the nature of FG-IR-24-282 vulnerability?
FG-IR-24-282 is an Improper Neutralization of CRLF Sequences in HTTP Headers, commonly known as HTTP response splitting.