FortiWeb - Double free in pipe management
Summary
A double free vulnerability (CWE-415) in FortiWeb CLI may allow an authenticated, local attacker to achieve arbitrary code execution via specifically crafted commands
Version | Affected | Solution |
---|---|---|
FortiWeb 7.2 | Not affected | Not Applicable |
FortiWeb 7.0 | 7.0.0 through 7.0.3 | Upgrade to 7.0.4 or above |
Acknowledgement
Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.Timeline
2023-02-16: Initial publication