imPC@ndo IT

Tracker / CVE-2022-23439

CVE-2022-23439

Medium 4.7

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver

Affected products and versions

fortinet fortiadc · 5.4.0 → 6.2.4
fortinet fortiauthenticator · 6.3.0 → 6.3.4
fortinet fortiauthenticator · 6.4.0 → 6.4.2
fortinet fortiddos · 5.3.0 → 5.5.2
fortinet fortiddos-f · 6.1.0 → 6.3.4
fortinet fortimail · 6.4.0 → 7.0.4
fortinet fortindr
fortinet fortindr · 1.4.0 → 7.1.1
fortinet fortios · 6.0.0 → 7.0.6
fortinet fortios · 7.2.0 → 7.2.5
fortinet fortiproxy · 2.0.0 → 7.0.5
fortinet fortiproxy · 7.2.0 → 7.4.0
fortinet fortirecorder · 6.0.0 → 6.0.11
fortinet fortirecorder · 6.4.0 → 6.4.3
fortinet fortisoar · 6.4.0 → 7.3.0
fortinet fortiswitch · 6.4.0 → 7.0.5
fortinet fortitester · 3.7.0 → 7.2.2
fortinet fortivoice · 6.0.0 → 6.4.9
fortinet fortiwlc · 8.6.0 → 8.6.7

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References