An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2.2 through 3.2.4, FortiSandbox 3.1.5 allows attacker to information disclosure via HTTP get requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortisandbox | 4.4.0 | 4.4.5 |
| fortinet / fortisandbox | 3.2.2 | 4.2.7 |
| fortinet / fortisandbox | 3.1.5 | 3.1.5.x |