Potential Exposure of Sensitive Information Through Crafted HTTP or HTTPS Requests
CVE-2023-44255
4.1MEDIUM
What is CVE-2023-44255?
In Fortinet FortiManager prior to version 7.4.2, FortiAnalyzer prior to version 7.4.2, and FortiAnalyzer-BigData prior to version 7.2.5, an exposure of sensitive information allows a privileged attacker with administrative read permissions to potentially access event logs pertaining to another Administrative Domain (ADOM) through specially crafted HTTP or HTTPS requests. This flaw highlights the importance of securing event log access and ensuring that sensitive information remains isolated within configured administrative boundaries.
Affected Version(s)
FortiAnalyzer 7.4.0 <= 7.4.2
FortiAnalyzer 7.2.0 <= 7.2.3
FortiAnalyzer 7.0.0 <= 7.0.13