CVE-2024-45323

An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiedrmanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiedrmanager:6.0.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-10 15:15

Updated : 2024-09-20 16:23


NVD link : CVE-2024-45323

Mitre link : CVE-2024-45323

CVE.ORG link : CVE-2024-45323


JSON object : View

Products Affected

fortinet

  • fortiedrmanager
CWE
CWE-284

Improper Access Control

NVD-CWE-Other