CVE-2018-13379

Source
https://cve.org/CVERecord?id=CVE-2018-13379
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-13379.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-13379
Published
2019-06-04T21:29:00.233Z
Modified
2026-03-14T09:27:34.559984Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-13379.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "1.2.9"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2.0.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "5.4.6"
            },
            {
                "fixed": "5.4.13"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "5.6.3"
            },
            {
                "fixed": "5.6.8"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "6.0.0"
            },
            {
                "fixed": "6.0.5"
            }
        ]
    }
]