Private Personal Information Collection by Debug Bundle

Summary

An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in FortiDLP may allow an authenticated windows administrator to collect current user's email information

Version Affected Solution
FortiDLP 12.1 Not affected Not Applicable
FortiDLP 12.0 Not affected Not Applicable
FortiDLP 11.5 11.5 all versions Migrate to a fixed release
FortiDLP 11.4 11.4 all versions Migrate to a fixed release
FortiDLP 11.3 11.3 all versions Migrate to a fixed release
FortiDLP 11.2 11.2 all versions Migrate to a fixed release
FortiDLP 11.1 11.1 all versions Migrate to a fixed release
FortiDLP 11.0 11.0 all versions Migrate to a fixed release
FortiDLP 10.5 10.5 all versions Migrate to a fixed release
FortiDLP 10.4 10.4 all versions Migrate to a fixed release
FortiDLP 10.3 10.3 all versions Migrate to a fixed release
FortiDLP 6.0 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by developers of FortiDLP team.

Timeline

2025-10-14: Initial publication