Disclosure of Logs of Devices not belonging to the Current ADOM from Log View

Summary

An Exposure of Sensitive Information to an Unauthorized Actor [CWE-200] in the Log View component of FortiAnalyzer may allow a local authenticated user with admin privileges to view logs of devices not belonging to the current ADOM

Version Affected Solution
FortiAnalyzer 7.6 7.6.0 Upgrade to 7.6.1 or above
FortiAnalyzer 7.4 7.4.0 through 7.4.4 Upgrade to 7.4.5 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.7 Upgrade to 7.2.8 or above
FortiAnalyzer 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer 6.4 6.4 all versions Migrate to a fixed release

Timeline

2025-02-11: Initial publication