QID 377697
Date Published: 2022-10-31
QID 377697: FortiAnalyzer - Multiple Vulnerabilities in Apache Airflow (FG-IR-22-008)
Multiple Security advisories were released affecting the version of Apache Airflow library.
Affected Products
FortiAnalyzer version 7.0.2 and below.
FortiAnalyzer version 6.4.7 and below.
Other Fortinet products do not use the Apache Airflow library.
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiAnalyzer and FortiManager.
Vulnerable version may allow improper access control and execute unauthorized code or commands
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-049
Vendor References
- FG-IR-22-008 -
www.fortiguard.com/psirt/FG-IR-22-008
CVEs related to QID 377697
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-008 |
|