FG-IR-24-422: Disclosure of Logs of Devices not belonging to the Current ADOM from Log View
An Exposure of Sensitive Information to an Unauthorized Actor [CWE-200] in the Log View component of FortiAnalyzer may allow a local authenticated user with admin privileges to view logs of devices not belonging to the current ADOM
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-422?
The severity of FG-IR-24-422 falls under a critical category due to exposure of sensitive information.
How do I fix FG-IR-24-422?
To fix FG-IR-24-422, update FortiAnalyzer to version 7.6.1 or higher, or ensure you are on a remedy version for older releases.
Who is affected by FG-IR-24-422?
FG-IR-24-422 affects local authenticated users with admin privileges on FortiAnalyzer devices running vulnerable versions.
What type of vulnerability is FG-IR-24-422?
FG-IR-24-422 is classified as an Exposure of Sensitive Information to an Unauthorized Actor as per CWE-200.
What products are affected by FG-IR-24-422?
FG-IR-24-422 affects various versions of FortiAnalyzer, specifically those below 7.6.1, 7.4.5, and 7.2.8.