Read only administrator can see passwords' hashes

Summary

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb may allow an authenticated attacker to read password hashes of other administrators via CLI commands or HTTP requests.

Version Affected Solution
FortiWeb 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiWeb 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiWeb 7.0 7.0.0 through 7.0.8 Upgrade to 7.0.9 or above
FortiWeb 6.4 Not affected Not Applicable
FortiWeb 6.3 6.3 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Kushal Arvind Shah of Fortinet's FortiGuard Labs.

Timeline

2024-05-14: Initial publication