Enrollment code on install saved in log
Summary
An Insertion of Sensitive Information into Log File [CWE-532] vulnerability in FortiDLP Windows Agent installer may allow an authenticated attacker to pollute the agent pool via re-using the enrollment code.
| Version | Affected | Solution |
|---|---|---|
| FortiDLP 12.1 | Not affected | Not Applicable |
| FortiDLP 12.0 | 12.0 all versions | Migrate to a fixed release |
| FortiDLP 11.5 | 11.5 all versions | Migrate to a fixed release |
| FortiDLP 11.4 | 11.4.5 through 11.4.6 | Migrate to a fixed release |
| FortiDLP 11.2 | Not affected | Not Applicable |
| FortiDLP 10.4 | Not affected | Not Applicable |
| FortiDLP 6.0 | Not affected | Not Applicable |