PSIRT Advisories
FortiGate - Policy-based NGFW SSL VPN mode doesn't filter accesses via Bookmarks
Summary
A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal.
Affected Products
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
Solutions
Please upgrade to FortiOS version 7.2.4 or abovePlease upgrade to FortiOS version 7.0.11 or above