QID 44055

Date Published: 2023-05-31

QID 44055: FortiOS Information Disclosure Vulnerability in Web Proxy Error Pages (FG-IR-21-231) (Unauthenticated Check)

A server-generated error message containing sensitive information vulnerability [CWE-550] in FortiOS and FortiProxy web proxy may allow a malicious webserver to retrieve a web proxy's client username and IP via same origin HTTP requests triggering proxy-generated HTTP status codes pages.

Affected Products:
FortiOS version 7.0.3 and below
FortiOS version 6.4.9 and below
FortiOS version 6.2.10 and below
FortiOS version 6.0.14 and below

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Vulnerable FortiOS may allow a malicious web server to retrieve a web proxy's client username and IP via same origin HTTP requests triggering proxy-generated HTTP status codes pages.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-21-231

    Vendor References

    CVEs related to QID 44055

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-231 URL Logo www.fortiguard.com/psirt/FG-IR-21-231