FortiAIOps - Improper Session Management

Summary

Multiple insufficient session expiration vulnerabilities [CWE-613] in FortiAIOps may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.

Version Affected Solution
FortiAIOps 2.0 2.0.0 Upgrade to 2.0.1 or above

Acknowledgement

Internally discovered and reported by Shree Rawal of Fortinet PSIRT team.

Timeline

2024-07-09: Initial publication