Readonly user could execute sensitive operations
Summary
A client-side enforcement of server-side security vulnerability [CWE-602] in FortiSandbox may allow an authenticated attacker with at least read-only permission to download or upload configuration.
| Version | Affected | Solution |
|---|---|---|
| FortiSandbox 4.4 | 4.4.0 through 4.4.4 | Upgrade to 4.4.5 or above |
| FortiSandbox 4.2 | 4.2.1 through 4.2.6 | Upgrade to 4.2.7 or above |
| FortiSandbox 4.0 | Not affected | Not Applicable |
| FortiSandbox 3.2 | Not affected | Not Applicable |
Fortinet in Q3/24 has remediated this issue in FortiSandbox Cloud version 24.1 and hence the customers need not perform any action.
Acknowledgement
Internally discovered and reported by Adham El karn of Fortinet Product Security team.Timeline
2024-05-14: Initial publication2025-05-07: Clarify fix information for FortiSandbox Cloud product