Missing authorization on log access
Summary
A Direct Request ('Forced Browsing') [CWE-425] vulnerability in FortiAuthenticator logs may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints.
| Version | Affected | Solution |
|---|---|---|
| FortiAuthenticator 8.0 | Not affected | Not Applicable |
| FortiAuthenticator 6.6 | 6.6.0 through 6.6.6 | Upgrade to 6.6.7 or above |
| FortiAuthenticator 6.5 | 6.5 all versions | Migrate to a fixed release |
| FortiAuthenticator 6.4 | 6.4 all versions | Migrate to a fixed release |
| FortiAuthenticator 6.3 | 6.3 all versions | Migrate to a fixed release |