FortiWeb - Double free in pipe management

Summary

A double free vulnerability (CWE-415) in FortiWeb CLI may allow an authenticated, local attacker to achieve arbitrary code execution via specifically crafted commands

Version Affected Solution
FortiWeb 7.2 Not affected Not Applicable
FortiWeb 7.0 7.0.0 through 7.0.3 Upgrade to 7.0.4 or above

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.

Timeline

2023-02-16: Initial publication