An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2.2 through 3.2.4, FortiSandbox 3.1.5 allows attacker to information disclosure via HTTP get requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.com/psirt/FG-IR-24-051 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
14 Jan 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2.2 through 3.2.4, FortiSandbox 3.1.5 allows attacker to information disclosure via HTTP get requests. | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
20 Sep 2024, 19:48
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| References | () https://fortiguard.com/psirt/FG-IR-24-051 - Vendor Advisory | |
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:3.1.5:*:*:*:*:*:*:* |
|
| First Time |
Fortinet
Fortinet fortisandbox |
|
| Summary |
|
10 Sep 2024, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-09-10 15:15
Updated : 2026-01-14 14:16
NVD link : CVE-2024-31490
Mitre link : CVE-2024-31490
CVE.ORG link : CVE-2024-31490
JSON object : View
Products Affected
fortinet
- fortisandbox
CWE
