Privilege escalation from nginx user to root
Summary
An improper privilege management vulnerability [CWE-269] in FortiSOAR may allow a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
| Version | Affected | Solution |
|---|---|---|
| FortiSOAR on-premise 7.2 | 7.2.0 | Upgrade to 7.2.1 or above |
| FortiSOAR on-premise 7.0 | 7.0.0 through 7.0.2 | Upgrade to 7.0.3 or above |
| FortiSOAR on-premise 6.4 | 6.4 all versions | Migrate to a fixed release |