<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Unauthenticated access to static files containing logging information</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-364</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-03-07T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-03-07T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2023-03-07T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiOS and FortiProxy administrative interface may allow an unauthenticated attacker to obtain sensitive logging information on the device via crafted HTTP or HTTPs GET requests.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Improper access control
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiProxy version 7.2.0 through 7.2.2FortiProxy version 7.0.0 through 7.0.8FortiProxy 2.0 all versions are not affectedFortiProxy 1.2 all versions are not affectedFortiProxy 1.1 all versions are not affectedFortiOS version 7.2.0 through 7.2.3FortiOS version 7.0.0 through 7.0.9FortiOS version 6.4.0 through 6.4.11FortiOS version 6.2.3 through 6.2.17
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiProxy version 7.2.3 or abovePlease upgrade to FortiProxy version 7.0.9 or abovePlease upgrade to FortiOS version 7.2.4 or abovePlease upgrade to FortiOS version 7.0.10 or abovePlease upgrade to FortiOS version 6.4.12 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered and reported by Théo Leleu of Fortinet Product Security team.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiOS" Type="Product Name">
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.2.3">FortiOS 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.2.2">FortiOS 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.2.1">FortiOS 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.2.0">FortiOS 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.9">FortiOS 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.8">FortiOS 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.7">FortiOS 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.6">FortiOS 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.5">FortiOS 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.4">FortiOS 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.3">FortiOS 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.2">FortiOS 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.1">FortiOS 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.0">FortiOS 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.11" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.11">FortiOS 6.4.11</FullProductName>
                </Branch>
                <Branch Name="6.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.10">FortiOS 6.4.10</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.9">FortiOS 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.8">FortiOS 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.7">FortiOS 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.6">FortiOS 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.5">FortiOS 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.4">FortiOS 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.3">FortiOS 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.2">FortiOS 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.1">FortiOS 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.0">FortiOS 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.2.17" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.17">FortiOS 6.2.17</FullProductName>
                </Branch>
                <Branch Name="6.2.16" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.16">FortiOS 6.2.16</FullProductName>
                </Branch>
                <Branch Name="6.2.15" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.15">FortiOS 6.2.15</FullProductName>
                </Branch>
                <Branch Name="6.2.14" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.14">FortiOS 6.2.14</FullProductName>
                </Branch>
                <Branch Name="6.2.13" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.13">FortiOS 6.2.13</FullProductName>
                </Branch>
                <Branch Name="6.2.12" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.12">FortiOS 6.2.12</FullProductName>
                </Branch>
                <Branch Name="6.2.11" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.11">FortiOS 6.2.11</FullProductName>
                </Branch>
                <Branch Name="6.2.10" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.10">FortiOS 6.2.10</FullProductName>
                </Branch>
                <Branch Name="6.2.9" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.9">FortiOS 6.2.9</FullProductName>
                </Branch>
                <Branch Name="6.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.8">FortiOS 6.2.8</FullProductName>
                </Branch>
                <Branch Name="6.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.7">FortiOS 6.2.7</FullProductName>
                </Branch>
                <Branch Name="6.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.6">FortiOS 6.2.6</FullProductName>
                </Branch>
                <Branch Name="6.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.5">FortiOS 6.2.5</FullProductName>
                </Branch>
                <Branch Name="6.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.4">FortiOS 6.2.4</FullProductName>
                </Branch>
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.3">FortiOS 6.2.3</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiProxy" Type="Product Name">
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.2.2">FortiProxy 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.2.1">FortiProxy 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.2.0">FortiProxy 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.8">FortiProxy 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.7">FortiProxy 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.6">FortiProxy 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.5">FortiProxy 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.4">FortiProxy 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.3">FortiProxy 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.2">FortiProxy 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.1">FortiProxy 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.0">FortiProxy 7.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Unauthenticated access to static files containing logging information</Title>
        <cvrf:CVE>CVE-2022-41329</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiOS-7.2.3</ProductID>
                <ProductID>FortiOS-7.2.2</ProductID>
                <ProductID>FortiOS-7.2.1</ProductID>
                <ProductID>FortiOS-7.2.0</ProductID>
                <ProductID>FortiOS-7.0.9</ProductID>
                <ProductID>FortiOS-7.0.8</ProductID>
                <ProductID>FortiOS-7.0.7</ProductID>
                <ProductID>FortiOS-7.0.6</ProductID>
                <ProductID>FortiOS-7.0.5</ProductID>
                <ProductID>FortiOS-7.0.4</ProductID>
                <ProductID>FortiOS-7.0.3</ProductID>
                <ProductID>FortiOS-7.0.2</ProductID>
                <ProductID>FortiOS-7.0.1</ProductID>
                <ProductID>FortiOS-7.0.0</ProductID>
                <ProductID>FortiOS-6.4.11</ProductID>
                <ProductID>FortiOS-6.4.10</ProductID>
                <ProductID>FortiOS-6.4.9</ProductID>
                <ProductID>FortiOS-6.4.8</ProductID>
                <ProductID>FortiOS-6.4.7</ProductID>
                <ProductID>FortiOS-6.4.6</ProductID>
                <ProductID>FortiOS-6.4.5</ProductID>
                <ProductID>FortiOS-6.4.4</ProductID>
                <ProductID>FortiOS-6.4.3</ProductID>
                <ProductID>FortiOS-6.4.2</ProductID>
                <ProductID>FortiOS-6.4.1</ProductID>
                <ProductID>FortiOS-6.4.0</ProductID>
                <ProductID>FortiOS-6.2.17</ProductID>
                <ProductID>FortiOS-6.2.16</ProductID>
                <ProductID>FortiOS-6.2.15</ProductID>
                <ProductID>FortiOS-6.2.14</ProductID>
                <ProductID>FortiOS-6.2.13</ProductID>
                <ProductID>FortiOS-6.2.12</ProductID>
                <ProductID>FortiOS-6.2.11</ProductID>
                <ProductID>FortiOS-6.2.10</ProductID>
                <ProductID>FortiOS-6.2.9</ProductID>
                <ProductID>FortiOS-6.2.8</ProductID>
                <ProductID>FortiOS-6.2.7</ProductID>
                <ProductID>FortiOS-6.2.6</ProductID>
                <ProductID>FortiOS-6.2.5</ProductID>
                <ProductID>FortiOS-6.2.4</ProductID>
                <ProductID>FortiOS-6.2.3</ProductID>
                <ProductID>FortiProxy-7.2.2</ProductID>
                <ProductID>FortiProxy-7.2.1</ProductID>
                <ProductID>FortiProxy-7.2.0</ProductID>
                <ProductID>FortiProxy-7.0.8</ProductID>
                <ProductID>FortiProxy-7.0.7</ProductID>
                <ProductID>FortiProxy-7.0.6</ProductID>
                <ProductID>FortiProxy-7.0.5</ProductID>
                <ProductID>FortiProxy-7.0.4</ProductID>
                <ProductID>FortiProxy-7.0.3</ProductID>
                <ProductID>FortiProxy-7.0.2</ProductID>
                <ProductID>FortiProxy-7.0.1</ProductID>
                <ProductID>FortiProxy-7.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>5.2</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:X/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-364</URL>
                <Description>Unauthenticated access to static files containing logging information</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>