PT-2021-7554 · Fortinet · Fortisandbox
Published
2021-08-03
·
Updated
2021-08-11
·
CVE-2021-24010
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
FortiSandbox versions 3.1.0 through 3.1.4
FortiSandbox versions 3.2.0 through 3.2.2
Description
The issue is related to improper limitation of a pathname to a restricted directory in FortiSandbox. This can be exploited by a remote attacker using a specially crafted request to gain unauthorized access to protected information. An authenticated user may obtain unauthorized access to files and data via specifically crafted web requests.
Recommendations
For FortiSandbox versions 3.1.0 through 3.1.4, update to a version outside of this range to resolve the issue.
For FortiSandbox versions 3.2.0 through 3.2.2, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to sensitive directories and files to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortisandbox