Path traversal in history downloadzip

Summary

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.

Version Affected Solution
FortiAnalyzer 7.4 Not affected Not Applicable
FortiAnalyzer 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiAnalyzer 7.0 7.0.0 through 7.0.5 Upgrade to 7.0.7 or above
FortiAnalyzer 6.4 6.4.0 through 6.4.11 Upgrade to 6.4.12 or above
FortiAnalyzer 6.2 Not affected Not Applicable
FortiManager 7.4 Not affected Not Applicable
FortiManager 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiManager 7.0 7.0.0 through 7.0.5 Upgrade to 7.0.7 or above
FortiManager 6.4 6.4.0 through 6.4.10 Upgrade to 6.4.12 or above
FortiManager 6.2 6.2.11 Migrate to a fixed release

Timeline

2023-07-11: Initial publication