Insertion of sensitive information into Event log

Summary

An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiAnalyzer and FortiManager eventlog may allow any low privileged user with access to event log section to retrieve certificate private key and encrypted password logged as system log.  

Version Affected Solution
FortiAnalyzer 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above
FortiAnalyzer 7.0 7.0.0 through 7.0.8 Upgrade to 7.0.9 or above
FortiManager 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiManager 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above
FortiManager 7.0 7.0.0 through 7.0.8 Upgrade to 7.0.9 or above

Acknowledgement

Internally discovered and reported by June Li from Fortinet's QA team and Goutham Dhongadi from Fortinet's FortiGuard Labs .

Timeline

2025-02-11: Initial publication