Description
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Please upgrade to FortiSOAR version 7.3.1 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-29373 | An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses. |
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-052 |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 21 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortisoar |
|
| CPEs | cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortisoar |
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-02T01:52:57.311Z
Reserved: 2024-04-04T12:52:41.586Z
Link: CVE-2024-31493
Updated: 2024-06-03T14:11:18.534Z
Status : Analyzed
Published: 2024-06-03T08:15:09.097
Modified: 2025-01-21T21:49:55.390
Link: CVE-2024-31493
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD