QID 43907
Date Published: 2022-10-17
QID 43907: FortiOS Information Disclosure Vulnerability in Web Proxy Error Pages (FG-IR-21-231)
A server-generated error message containing sensitive information vulnerability [CWE-550] in FortiOS and FortiProxy web proxy may allow a malicious webserver to retrieve a web proxy's client username and IP via same origin HTTP requests triggering proxy-generated HTTP status codes pages.
Affected Products:
FortiOS version 7.0.3 and below
FortiOS version 6.4.9 and below
FortiOS version 6.2.10 and below
FortiOS version 6.0.14 and below
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable FortiOS may allow a malicious web server to retrieve a web proxy's client username and IP via same origin HTTP requests triggering proxy-generated HTTP status codes pages.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-231
- FG-IR-21-231 -
www.fortiguard.com/psirt/FG-IR-21-231
CVEs related to QID 43907
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-231 |
|