CVE-2023-45585 Information
Nov 15, 2023
cve
Description
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0 version 6.7.6 and below version 6.6.3 and below version 6.5.1 and below version 6.4.2 and below version 6.3.3 and below version 6.2.1 and below version 6.1.2 and below version 5.4.0 version 5.3.3 and below may allow an authenticated user to view an encrypted ElasticSearch password via debug log files generated when FortiSIEM is configured with ElasticSearch Event Storage.
Reference
https://fortiguard.com/psirt/FG-IR-23-392
Share on: