Path traversal vulnerabilities in the web API

Summary

Multiple relative path traversal vulnerabilities [CWE-23] in the web API of FortiSOAR may allow an authenticated attacker to write in the underlying filesystem with nginx permissions via crafted HTTP requests.

Version Affected Solution
FortiSOAR on-premise 7.2 7.2.0 Upgrade to 7.2.1 or above
FortiSOAR on-premise 7.0 7.0.0 through 7.0.2 Upgrade to 7.0.3 or above
FortiSOAR on-premise 6.4 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank security researchers Ryan Catterall and OJ Reeves of Beyond Binary for discovering and reporting this vulnerability under responsible disclosure.

Timeline

2022-09-06: Initial publication