Sensitive files disclosure in diagnostic logs download

Summary

An exposure of sensitive Information to an unauthorized actor vulnerability [CWE-200] in FortiSandbox may allow an authenticated attacker with at least read-only permission to read sensitive files via HTTP get requests.

Version Affected Solution
FortiSandbox 4.4 4.4.0 through 4.4.4 Upgrade to 4.4.5 or above
FortiSandbox 4.2 4.2.1 through 4.2.6 Upgrade to 4.2.7 or above
FortiSandbox 4.0 4.0 all versions Migrate to a fixed release
FortiSandbox 3.2 3.2.2 through 3.2.4 Migrate to a fixed release
FortiSandbox 3.1 3.1.5 Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2024-09-10: Initial publication