Policy-based NGFW SSL VPN mode doesn't filter accesses via Bookmarks

Summary

A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal.

Affected Products

FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9

Solutions

Please upgrade to FortiOS version 7.2.4 or above
Please upgrade to FortiOS version 7.0.11 or above

Acknowledgement

Fortinet is pleased to thank Mr. Salim Faid from JVGAS for bringing this issue to our attention under responsible disclosure.

Timeline

2023-03-17: Initial publication