CVE-2022-29062
published 2022-09-06CVE-2022-29062: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.72%
49.7th percentile
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortinet_fortisoar | — | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | >= 7.0.0 < 7.0.3 | 7.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-42g6-7w4j-xv9r: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7
ghsa_unreviewed·2022-09-07
CVE-2022-29062 [MEDIUM] CWE-22 GHSA-42g6-7w4j-xv9r: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
Fortinet
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated att...
vendor_fortinet·2022-09-06·CVSS 6.3
CVE-2022-29062 [MEDIUM] CWE-22 Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated att...
FG-IR-22-154: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated att...
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
CVEs: CVE-2022-29062
CWEs: CWE-22
CVSS: 6.3 (medium)
Affected products: FortiSOAR, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-06
Published