A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticated attacker with at least read-only admin permissions to view encrypted secrets via the FortiPortal System Log.
The product writes sensitive information to a log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortiportal | Fortinet | 7.0.0 (including) | 7.0.10 (excluding) |
Fortiportal | Fortinet | 7.2.0 (including) | 7.2.6 (excluding) |
Fortiportal | Fortinet | 7.4.0 (including) | 7.4.0 (including) |