FortiAnalyzer & FortiManager - Path traversal in history downloadzip
Summary
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Affected Products
FortiManager version 7.2.0 through 7.2.1
FortiManager version 7.0.0 through 7.0.5
FortiManager version 6.4.0 through 6.4.11
FortiAnalyzer version 7.2.0 through 7.2.1
FortiAnalyzer version 7.0.0 through 7.0.5
FortiAnalyzer version 6.4.0 through 6.4.11
Solutions
Please upgrade to FortiManager version 7.2.2 or abovePlease upgrade to FortiManager version 7.0.7 or above
Please upgrade to FortiManager version 6.4.12 or above
Please upgrade to FortiAnalyzer version 7.2.2 or above
Please upgrade to FortiAnalyzer version 7.0.7 or above
Please upgrade to FortiAnalyzer version 6.4.12 or above
Timeline
2023-06-19: Initial publication