Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r99-7p57-xjr3

Опубликовано: 10 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions when cookie security policy is enabled may allow an attacker, under specific conditions, to retrieve the initial encrypted and signed cookie protected by the feature

An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions when cookie security policy is enabled may allow an attacker, under specific conditions, to retrieve the initial encrypted and signed cookie protected by the feature

EPSS

Процентиль: 32%
0.00379
Низкий

3.7 Low

CVSS3

Дефекты

CWE-358

Связанные уязвимости

CVSS3: 3.7
nvd
около 2 лет назад

An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions when cookie security policy is enabled may allow an attacker, under specific conditions, to retrieve the initial encrypted and signed cookie protected by the feature

CVSS3: 3.7
fstec
около 2 лет назад

Уязвимость компонента Web Application Firewall контроллера доставки приложений Fortinet FortiADC, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 32%
0.00379
Низкий

3.7 Low

CVSS3

Дефекты

CWE-358