FortiAIOps - Sensitive Information leak to an Unauthorized Actor

Summary

Multiple Exposure of sensitive information to an unauthorized actor vulnerabilities [CWE-200] may allow an authenticated attacker to retrieve sensitive information from the API endpoint or logs.

Version Affected Solution
FortiAIOps 2.0 2.0.0 Upgrade to 2.0.1 or above

Acknowledgement

Internally discovered and reported by Shree Rawal and Jenny Ning of Fortinet PSIRT team.

Timeline

2024-07-09: Initial publication