FortiPortal - XML parser is vulnerable to XXE attacks
Fortinet PSIRT Advisories
Fortinet PSIRT Contact:
Website: https://fortiguard.fortinet.com/faq/psirt-contact
FG-IR-21-104
Final
1
1
2021-11-02T00:00:00
Current version
2021-11-02T00:00:00
2021-11-02T00:00:00
An improper restriction of XML external entity reference vulnerability [CWE-611] in the parser of XML responses of FortiPortal may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from the underlying file system by means of specifically crafted XML documents.
Information disclosure
FortiPortal version 6.0.5 and below. FortiPortal version 5.3.6 and below. FortiPortal version 5.2.6 and below. FortiPortal version 5.1.2 and below. FortiPortal version 5.0.3 and below. FortiPortal version 4.2.4 and below. FortiPortal version 4.1.2 and below. FortiPortal version 4.0.4 and below.
Upgrade to FortiPortal version 6.0.6 or above. Upgrade to FortiPortal version 5.3.7 or above. Upgrade to FortiPortal version 5.2.7 or above.
Internally discovered and reported by Giuseppe Cocomazzi of Fortinet Product Security team.
FortiPortal 6.0.5
FortiPortal 6.0.4
FortiPortal 6.0.3
FortiPortal 6.0.2
FortiPortal 6.0.1
FortiPortal 6.0.0
FortiPortal 5.3.6
FortiPortal 5.3.5
FortiPortal 5.3.4
FortiPortal 5.3.3
FortiPortal 5.3.2
FortiPortal 5.3.1
FortiPortal 5.3.0
FortiPortal 5.2.6
FortiPortal 5.2.5
FortiPortal 5.2.4
FortiPortal 5.2.3
FortiPortal 5.2.2
FortiPortal 5.2.1
FortiPortal 5.2.0
FortiPortal 5.1.2
FortiPortal 5.1.1
FortiPortal 5.1.0
FortiPortal 5.0.3
FortiPortal 5.0.2
FortiPortal 5.0.1
FortiPortal 5.0.0
FortiPortal 4.2.2
FortiPortal 4.2.1
FortiPortal 4.1.2
FortiPortal 4.1.1
FortiPortal 4.1.0
FortiPortal 4.0.4
FortiPortal 4.0.3
FortiPortal 4.0.2
FortiPortal 4.0.1
FortiPortal 4.0.0
FortiPortal - XML parser is vulnerable to XXE attacks
CVE-2021-36172
FortiPortal-6.0.5
FortiPortal-6.0.4
FortiPortal-6.0.3
FortiPortal-6.0.2
FortiPortal-6.0.1
FortiPortal-6.0.0
FortiPortal-5.3.6
FortiPortal-5.3.5
FortiPortal-5.3.4
FortiPortal-5.3.3
FortiPortal-5.3.2
FortiPortal-5.3.1
FortiPortal-5.3.0
FortiPortal-5.2.6
FortiPortal-5.2.5
FortiPortal-5.2.4
FortiPortal-5.2.3
FortiPortal-5.2.2
FortiPortal-5.2.1
FortiPortal-5.2.0
FortiPortal-5.1.2
FortiPortal-5.1.1
FortiPortal-5.1.0
FortiPortal-5.0.3
FortiPortal-5.0.2
FortiPortal-5.0.1
FortiPortal-5.0.0
FortiPortal-4.2.2
FortiPortal-4.2.1
FortiPortal-4.1.2
FortiPortal-4.1.1
FortiPortal-4.1.0
FortiPortal-4.0.4
FortiPortal-4.0.3
FortiPortal-4.0.2
FortiPortal-4.0.1
FortiPortal-4.0.0
3.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:W/RC:C
https://fortiguard.fortinet.com/psirt/FG-IR-21-104
FortiPortal - XML parser is vulnerable to XXE attacks
Reference>