2024-04-10 19:00:51 +00:00
{
2024-09-10 15:00:36 +00:00
"data_version" : "4.0" ,
2024-04-10 19:00:51 +00:00
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"CVE_data_meta" : {
"ID" : "CVE-2024-31490" ,
2024-09-10 15:00:36 +00:00
"ASSIGNER" : "psirt@fortinet.com" ,
"STATE" : "PUBLIC"
2024-04-10 19:00:51 +00:00
} ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2024-09-10 15:00:36 +00:00
"value" : "An exposure of sensitive information to an unauthorized actor in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.2 through 3.2.4 and 3.1.5 allows attacker to information disclosure via HTTP get requests."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "Information disclosure" ,
"cweId" : "CWE-200"
}
]
}
]
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "Fortinet" ,
"product" : {
"product_data" : [
{
"product_name" : "FortiSandbox" ,
"version" : {
"version_data" : [
{
"version_affected" : "<=" ,
"version_name" : "4.4.0" ,
"version_value" : "4.4.4"
} ,
{
"version_affected" : "<=" ,
"version_name" : "4.2.0" ,
"version_value" : "4.2.6"
} ,
{
"version_affected" : "<=" ,
"version_name" : "4.0.0" ,
"version_value" : "4.0.5"
} ,
{
"version_affected" : "<=" ,
"version_name" : "3.2.2" ,
"version_value" : "3.2.4"
} ,
{
"version_affected" : "=" ,
"version_value" : "3.1.5"
}
]
}
}
]
}
}
]
}
} ,
"references" : {
"reference_data" : [
{
"url" : "https://fortiguard.com/psirt/FG-IR-24-051" ,
"refsource" : "MISC" ,
"name" : "https://fortiguard.com/psirt/FG-IR-24-051"
}
]
} ,
"solution" : [
{
"lang" : "en" ,
"value" : "Please upgrade to FortiSandbox version 4.4.5 or above \nPlease upgrade to FortiSandbox version 4.2.7 or above"
}
] ,
"impact" : {
"cvss" : [
{
"version" : "3.1" ,
"attackComplexity" : "LOW" ,
"attackVector" : "NETWORK" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.2 ,
"baseSeverity" : "MEDIUM" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"privilegesRequired" : "LOW" ,
"scope" : "UNCHANGED" ,
"userInteraction" : "NONE" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:F/RL:X/RC:X"
2024-04-10 19:00:51 +00:00
}
]
}
}