FortiManager - Code Injection via Jinja Template
Summary
An improper neutralization of special elements used in a template engine [CWE-1336] vulnerability in FortiManager provisioning templates may allow a local authenticated attacker with at least read-only permissions to execute arbitrary code via specially crafted templates.
| Version | Affected | Solution |
|---|---|---|
| FortiManager 7.4 | 7.4.0 through 7.4.1 | Upgrade to 7.4.2 or above |
| FortiManager 7.2 | 7.2.0 through 7.2.4 | Upgrade to 7.2.5 or above |
| FortiManager 7.0 | 7.0.0 through 7.0.10 | Upgrade to 7.0.11 or above |
| FortiManager 6.4 | Not affected | Not Applicable |
Workaround- Disable "Provisioning Templates" and "Install Policy Package or Device Configuration" privileges unless strictly necessary.