Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfvw-qgrv-hgv6

Опубликовано: 10 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a system where the agent is deployed, via sending a crafted request to the agent port.

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a system where the agent is deployed, via sending a crafted request to the agent port.

EPSS

Процентиль: 38%
0.00465
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.8
nvd
5 месяцев назад

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a system where the agent is deployed, via sending a crafted request to the agent port.

CVSS3: 5.8
fstec
5 месяцев назад

Уязвимость программного обеспечения Fortinet FortiSOAR Agent Communication Bridge, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных

EPSS

Процентиль: 38%
0.00465
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-22