Read-only admin could obtain admin configuration secrets
Summary
An improper access control vulnerability [CWE-284] in FortiAuthenticator Web UI may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests.
| Version | Affected | Solution |
|---|---|---|
| FortiAuthenticator 8.0 | Not affected | Not Applicable |
| FortiAuthenticator 6.6 | 6.6.0 through 6.6.6 | Upgrade to 6.6.7 or above |
| FortiAuthenticator 6.5 | 6.5 all versions | Migrate to a fixed release |
| FortiAuthenticator 6.4 | 6.4 all versions | Migrate to a fixed release |
| FortiAuthenticator 6.3 | 6.3 all versions | Migrate to a fixed release |