Path traversal vulnerability

Summary

Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface may allow a remote and authenticated attacker to retrieve and delete arbitrary files from the underlying filesystem via specially crafted web requests.

Affected Products

FortiDeceptor version 1.0.0 through 1.0.1
FortiDeceptor version 1.1.0
FortiDeceptor version 2.0.0
FortiDeceptor version 2.1.0
FortiDeceptor version 3.0.0 through 3.0.2
FortiDeceptor version 3.1.0 through 3.1.1
FortiDeceptor version 3.2.0 through 3.2.2
FortiDeceptor version 3.3.0 through 3.3.2
FortiDeceptor version 4.0.0 through 4.0.1

Solutions

Please upgrade to FortiDeceptor version 4.1.0 or above
Please upgrade to FortiDeceptor version 4.0.2 or above
Please upgrade to FortiDeceptor version 3.3.3 or above

Acknowledgement

Internally discovered and reported by Wilfried Djettchou of Fortinet Product Security team.