FortiAIOps - Improper Session Management
Summary
Multiple insufficient session expiration vulnerabilities [CWE-613] in FortiAIOps may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.
Version | Affected | Solution |
---|---|---|
FortiAIOps 2.0 | 2.0.0 | Upgrade to 2.0.1 or above |
Acknowledgement
Internally discovered and reported by Shree Rawal of Fortinet PSIRT team.Timeline
2024-07-09: Initial publication