Policy-based NGFW SSL VPN mode doesn't filter accesses via Bookmarks
Summary
A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal.
Affected Products
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
Solutions
Please upgrade to FortiOS version 7.2.4 or above
Please upgrade to FortiOS version 7.0.11 or above
Acknowledgement
Fortinet is pleased to thank Mr. Salim Faid from JVGAS for bringing this issue to our attention under responsible disclosure.Timeline
2023-04-11: Initial publication