Code injection in playbook code snippet step

Summary

An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR may allow an authenticated attacker to execute arbitrary code on the host via a playbook code snippet.

Version Affected Solution
FortiSOAR 7.5 Not affected Not Applicable
FortiSOAR 7.4 7.4 all versions Upgrade to FortiSOAR Code Snippet Connector version 2.1.0 or above
FortiSOAR 7.3 7.3 all versions Upgrade to FortiSOAR Code Snippet Connector version 2.1.0 or above
FortiSOAR 7.2 7.2 all versions Upgrade to FortiSOAR Code Snippet Connector version 2.1.0 or above
FortiSOAR 7.0 7.0 all versions Upgrade to FortiSOAR Code Snippet Connector version 2.1.0 or above
FortiSOAR 6.4 6.4 all versions Upgrade to FortiSOAR Code Snippet Connector version 2.1.0 or above

Acknowledgement

Fortinet is pleased to thank Bilal Alqurneh for reporting this vulnerability under responsible disclosure

Timeline

2024-05-14: Initial publication