FG-IR-26-152: Header injection in Web Filter warning page
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-152?
The severity of FG-IR-26-152 is classified as low with a score of 3.4.
How do I fix FG-IR-26-152?
To fix FG-IR-26-152, ensure that users are made aware of the risks associated with clicking unknown links and monitor for any misuse of web filter override tokens.
What platforms are affected by FG-IR-26-152?
FG-IR-26-152 affects Fortinet FortiOS and Fortinet FortiProxy.
What type of attack does FG-IR-26-152 facilitate?
FG-IR-26-152 facilitates an HTTP Response Splitting attack, allowing the injection of arbitrary headers.
What should organizations do regarding FG-IR-26-152?
Organizations should regularly update their Fortinet systems and educate their users about the phishing risks associated with crafted links.