Lucene search

K
fortinetFortiGuard LabsFG-IR-21-231
HistoryMay 03, 2022 - 12:00 a.m.

Protect

2022-05-0300:00:00
FortiGuard Labs
www.fortiguard.com
62
vulnerability
server error
fortios
fortiproxy
web proxy
sensitive information
malicious webserver
http requests
http status codes

EPSS

0.001

Percentile

31.3%

A server-generated error message containing sensitive information vulnerability [CWE-550] in FortiOS and FortiProxy web proxy may allow a malicious webserver to retrieve a web proxy’s client username and IP via same origin HTTP requests triggering proxy-generated HTTP status codes pages.

EPSS

0.001

Percentile

31.3%

Related for FG-IR-21-231