SSRF in GUI console
Summary
A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] in FortiSandbox may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP requests.
| Version | Affected | Solution |
|---|---|---|
| FortiSandbox 5.0 | 5.0.0 through 5.0.4 | Upgrade to 5.0.5 or above |
| FortiSandbox 4.4 | 4.4 all versions | Migrate to a fixed release |
| FortiSandbox 4.2 | 4.2 all versions | Migrate to a fixed release |
| FortiSandbox 4.0 | 4.0 all versions | Migrate to a fixed release |