SSRF in FortiGuard Outbreak feature

Summary

A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests.

Version Affected Solution
FortiAnalyzer 7.4 Not affected Not Applicable
FortiAnalyzer 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiAnalyzer 7.0 7.0.0 through 7.0.6 Upgrade to 7.0.7 or above
FortiAnalyzer 6.4 6.4.8 through 6.4.11 Upgrade to 6.4.12 or above
FortiAnalyzer 6.2 Not affected Not Applicable
FortiManager 7.4 Not affected Not Applicable
FortiManager 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiManager 7.0 7.0.0 through 7.0.6 Upgrade to 7.0.7 or above
FortiManager 6.4 6.4.8 through 6.4.11 Upgrade to 6.4.12 or above
FortiManager 6.2 Not affected Not Applicable

Timeline

2023-06-12: Initial publication