FortiAuthenticator - Open Redirect on /portal/disclaimer

Summary

A URL redirection to untrusted site ('Open Redirect') (CWE-601) vulnerability in FortiAuthenticator may allow an attacker to redirect users to an arbitrary website via a crafted URL.

Version Affected Solution
FortiAuthenticator 6.6 6.6.0 Upgrade to 6.6.1 or above
FortiAuthenticator 6.5 6.5.0 through 6.5.3 Upgrade to 6.5.4 or above
FortiAuthenticator 6.4 6.4 all versions Migrate to a fixed release
FortiAuthenticator 6.3 Not affected Not Applicable
FortiAuthenticator 6.2 Not affected Not Applicable
FortiAuthenticator 6.1 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank MOD from Cheops Cyberdefense for reporting this vulnerability under responsible disclosure.

Timeline

2024-05-14: Initial publication