Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The resolved issues listed below may not list every bug that has been corrected with this release. For inquiries about a particular bug, please contact Technical Support within the FortiCare portal.

Secret/Launch

Bug ID

Description

1243034 Change "Username" and "Password" in default template of "Windows Machine" from Required to Optional.
1200794 Network mapping using secret probing on FortiPAM.

1268756

Explicit Web Proxy Certificate Import GUI vs CLI bevhaviour.

1198058

Web launcher is disabled after importing secret.

1256560

AV-profile is removed when attempting to save changes.

1239711

Customized resolution on Web RDP not available when accessing secrets from the secrets details page.

1237851

Replace Web Credential on Proxy does not work with Associated Secret enabled.

1238033

Error message "Unable to launch secret, request too frequently" when using a native launcher.

1193572

FortiPAM gateway access control.

1228329

Slow web SMB/SFTP file upload speed (1Mbps).

1237849

Add URL decode in the gateway info handler.

1050328

Approver unable to revoke the secret.

1273260

Secret Password Changer Fails for Azure AD web-api password changer.

1276453

Domain field does not accept domains starting with a number.

System/Log

Bug ID

Description

1257731

SFTP Config Backup to a remote server does not work.

1263941

No secret logs are send through syslog in version 1.8.0 nor 1.8.1.

1253814

Unable to view the logs on the FortiPAM when secretgrp set to custom.

1263843

FortiPAM HA synchronization issue caused by some fields missing in the EMS tag.

1260462

HA out of sync because secret target cannot be added into the secondary due to duplicate.

1235477

Changing to concurrent license causes FortiPAM to deny all logins via GUI.

1279383

Stack Buffer Overflow in Log Report.

Others

Bug ID

Description

1243837

FortiPAM 1100G/3100G chassis UID button does not function.

1246179

SSL-VPN Reflected XSS.

1201838

Stack buffer overflow in CLI.

1217886

port FortiOS bug fix for potential html injection.

1242213

Arbitrary file write via /api/usrbwl and /api/usrbwlqry endpoints.

1241847

Fabric connector with EMS 7.4.5 no longer works.

1256882

Agentless only not working on Edge/Chrome.

1242162

Evaluate path in "exec usb-disk delete" command.

1274827

API return code when querying target might be incorrect.

1275950

Wrong API return code for /api/v2/utility/id.

Common Vulnerabilities and Exposures

Bug ID

CVE references

1055670

FortiPAM is no longer vulnerable to the following CVE-Reference(s):

  • CVE-2024-3596

Visit https://fortiguard.com/psirt for more information.

Resolved issues

Resolved issues

The resolved issues listed below may not list every bug that has been corrected with this release. For inquiries about a particular bug, please contact Technical Support within the FortiCare portal.

Secret/Launch

Bug ID

Description

1243034 Change "Username" and "Password" in default template of "Windows Machine" from Required to Optional.
1200794 Network mapping using secret probing on FortiPAM.

1268756

Explicit Web Proxy Certificate Import GUI vs CLI bevhaviour.

1198058

Web launcher is disabled after importing secret.

1256560

AV-profile is removed when attempting to save changes.

1239711

Customized resolution on Web RDP not available when accessing secrets from the secrets details page.

1237851

Replace Web Credential on Proxy does not work with Associated Secret enabled.

1238033

Error message "Unable to launch secret, request too frequently" when using a native launcher.

1193572

FortiPAM gateway access control.

1228329

Slow web SMB/SFTP file upload speed (1Mbps).

1237849

Add URL decode in the gateway info handler.

1050328

Approver unable to revoke the secret.

1273260

Secret Password Changer Fails for Azure AD web-api password changer.

1276453

Domain field does not accept domains starting with a number.

System/Log

Bug ID

Description

1257731

SFTP Config Backup to a remote server does not work.

1263941

No secret logs are send through syslog in version 1.8.0 nor 1.8.1.

1253814

Unable to view the logs on the FortiPAM when secretgrp set to custom.

1263843

FortiPAM HA synchronization issue caused by some fields missing in the EMS tag.

1260462

HA out of sync because secret target cannot be added into the secondary due to duplicate.

1235477

Changing to concurrent license causes FortiPAM to deny all logins via GUI.

1279383

Stack Buffer Overflow in Log Report.

Others

Bug ID

Description

1243837

FortiPAM 1100G/3100G chassis UID button does not function.

1246179

SSL-VPN Reflected XSS.

1201838

Stack buffer overflow in CLI.

1217886

port FortiOS bug fix for potential html injection.

1242213

Arbitrary file write via /api/usrbwl and /api/usrbwlqry endpoints.

1241847

Fabric connector with EMS 7.4.5 no longer works.

1256882

Agentless only not working on Edge/Chrome.

1242162

Evaluate path in "exec usb-disk delete" command.

1274827

API return code when querying target might be incorrect.

1275950

Wrong API return code for /api/v2/utility/id.

Common Vulnerabilities and Exposures

Bug ID

CVE references

1055670

FortiPAM is no longer vulnerable to the following CVE-Reference(s):

  • CVE-2024-3596

Visit https://fortiguard.com/psirt for more information.