A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
References
Link | Resource |
---|---|
https://fortiguard.com/advisory/FG-IR-18-388 | Vendor Advisory |
https://fortiguard.com/advisory/FG-IR-20-229 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-05-29 11:29
Updated : 2021-03-16 08:48
NVD link : CVE-2018-13383
Mitre link : CVE-2018-13383
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
fortinet
- fortios
- fortiproxy