Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.0.12. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID

Description

772418

Fix ICAP client not forwarding response when host matches FQDN.

834299

SSH command filter no longer works after prompt change.

861899

FortiView Application Bandwidth widget shows nothing.

870099

LDAP cache was not updated properly after the user group changed in Active Directory server.

873073

WAD debug filter does not work properly with SSL deep-inspection using hardware crypto.

876758

SSH public keys are lost after upgrading from Beta 1 to latest interim build, and they can no longer be configured.

877836

Multiple attempts to join a domain with wrong credentials causes WAD to crash.

883131

Correlation log does not show security action when application category is unknown.

892116

Issue with the WAD debug filter on vd_id and dst6 or src6.

896345

Fine-grained user/group level authorization timeout configuration.

896476

FortiProxy rejects CONNECT request with body and extra data.

903925, 923610, 923847, 931277, 932620, 932623, 912281, 928710, 938018, 934477

Fix some GUI issues.

905188

Unexpect hang-up on FPX-4000E.

909271

Authenticated users using an IP-based authentication rule may need to be re-authenticated per request.

910329

Clean up HA Active-Active mode related CLI options.

913013

Update voltage monitoring with official Supermicro values.

913705, 913955

Remove extended-log option in AV/FF/DLP and extend log-http-transaction to three options: all, utm, and disable.

914303

HTTP transaction log is recorded as "https" scheme for "Ftp over HTTP" transaction.

914533

FortiGate DLP filter EXE files does not work on Windows.

917330

Some non-http traffic was redirected to WAD unexpectedly when L7 address exists in policy.

917412

FPX-2000G and FPX-4000G STA and UID LED color issue.

919643

FortiProxy kernel memory leak.

920083

EIP of mgmt-intf is mistakenly moved from secondary FPX to the primary in an AWS A-P HA cluster.

921158

Issue with format string that causes httpsd and CLI crash.

921642

Memory leak in client certificate cache for virtual server access proxy.

921902

LDAP search type default is unset due to an incorrect default value.

924449

Shaping policy matching failure.

924524

WAD crashes at wad_fw_policy_check_user when authorization is required for FTPS login on the FortiProxy.

924586

FortiProxy HA config-sync-only secondaries receive system updates triggered by both updated and hasync.

924740

Need to verify filters of wad debug trace and make sure all the necessary info is logged and filter works properly.

924919

Explicit FTPS authentication with transparent policy does not work.

925043

FortiProxy trial license is invalid when memory is more than 2 GB while the minimum required memory is 4GB.

926178, 930776

Add option to enable/disable application level category policy match for deep inspection .

926491

WAD policy matching crashed at matching the source address due to null source and destination addresses in dummy policy.

926927

Fix for a crash caused by a missing safe check during code porting.

927004

Validate address group members when config is loaded. If an error occurs while loading iptables rules for a specific policy, skip only the malformed policy instead of aborting the policy loading as a whole.

927838

FortiProxy matches user to wrong user group and hits the wrong policy.

928979

When multiple ports are configured for a firewall policy's service, only traffic to the first port matches the policy.

929971

Fix scanunit error logs on non-error case.

931778

Fix HTTP request to FQDN address not directed to WAN when dst_address includes wildcard FQDN.

932475

FortiProxy not showing proxy policy after restoring the configuration, but it is shown in the CLI.

932487

WAD worker memory usage slowly increased.

933593

Show full user-agent in the http-transaction log when extended-log is enabled

935749

Explicit policy was not added to policy list when the policy changes its web-proxy.

936409

FortiProxy did not support nested addrgrp definition, which caused a configuration error while upgrading.

929821

"Bad gateway" error message and httpsd process exits with segmentation fault when generating a TAC report from GUI.

927316

SNAT uses interface IP address instead of address from IP pool with forward server.

933030

Disable netflow and sflow commands which are not supported by FortiProxy.

933588

Build compile error during upgrade.

934498

When log-http-transaction is enabled, forward traffic to WAD only when UTM is enabled or the action of the policy is deny.

939241

939575

High CPU when DNS server is busy.

939160

WAD crash on traffic when VDOM is enabled and a global webfilter profile is attached to a policy.

935917

The respective corresponding sandbox should be displayed correctly.

936513

DNS is not updated with HA reserved mgmt interface..

Common vulnerabilities and exposures

FortiProxy 7.0.12 is no longer vulnerable to the following CVE reference. Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE reference

923315

CVE-2023-45583

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.0.12. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID

Description

772418

Fix ICAP client not forwarding response when host matches FQDN.

834299

SSH command filter no longer works after prompt change.

861899

FortiView Application Bandwidth widget shows nothing.

870099

LDAP cache was not updated properly after the user group changed in Active Directory server.

873073

WAD debug filter does not work properly with SSL deep-inspection using hardware crypto.

876758

SSH public keys are lost after upgrading from Beta 1 to latest interim build, and they can no longer be configured.

877836

Multiple attempts to join a domain with wrong credentials causes WAD to crash.

883131

Correlation log does not show security action when application category is unknown.

892116

Issue with the WAD debug filter on vd_id and dst6 or src6.

896345

Fine-grained user/group level authorization timeout configuration.

896476

FortiProxy rejects CONNECT request with body and extra data.

903925, 923610, 923847, 931277, 932620, 932623, 912281, 928710, 938018, 934477

Fix some GUI issues.

905188

Unexpect hang-up on FPX-4000E.

909271

Authenticated users using an IP-based authentication rule may need to be re-authenticated per request.

910329

Clean up HA Active-Active mode related CLI options.

913013

Update voltage monitoring with official Supermicro values.

913705, 913955

Remove extended-log option in AV/FF/DLP and extend log-http-transaction to three options: all, utm, and disable.

914303

HTTP transaction log is recorded as "https" scheme for "Ftp over HTTP" transaction.

914533

FortiGate DLP filter EXE files does not work on Windows.

917330

Some non-http traffic was redirected to WAD unexpectedly when L7 address exists in policy.

917412

FPX-2000G and FPX-4000G STA and UID LED color issue.

919643

FortiProxy kernel memory leak.

920083

EIP of mgmt-intf is mistakenly moved from secondary FPX to the primary in an AWS A-P HA cluster.

921158

Issue with format string that causes httpsd and CLI crash.

921642

Memory leak in client certificate cache for virtual server access proxy.

921902

LDAP search type default is unset due to an incorrect default value.

924449

Shaping policy matching failure.

924524

WAD crashes at wad_fw_policy_check_user when authorization is required for FTPS login on the FortiProxy.

924586

FortiProxy HA config-sync-only secondaries receive system updates triggered by both updated and hasync.

924740

Need to verify filters of wad debug trace and make sure all the necessary info is logged and filter works properly.

924919

Explicit FTPS authentication with transparent policy does not work.

925043

FortiProxy trial license is invalid when memory is more than 2 GB while the minimum required memory is 4GB.

926178, 930776

Add option to enable/disable application level category policy match for deep inspection .

926491

WAD policy matching crashed at matching the source address due to null source and destination addresses in dummy policy.

926927

Fix for a crash caused by a missing safe check during code porting.

927004

Validate address group members when config is loaded. If an error occurs while loading iptables rules for a specific policy, skip only the malformed policy instead of aborting the policy loading as a whole.

927838

FortiProxy matches user to wrong user group and hits the wrong policy.

928979

When multiple ports are configured for a firewall policy's service, only traffic to the first port matches the policy.

929971

Fix scanunit error logs on non-error case.

931778

Fix HTTP request to FQDN address not directed to WAN when dst_address includes wildcard FQDN.

932475

FortiProxy not showing proxy policy after restoring the configuration, but it is shown in the CLI.

932487

WAD worker memory usage slowly increased.

933593

Show full user-agent in the http-transaction log when extended-log is enabled

935749

Explicit policy was not added to policy list when the policy changes its web-proxy.

936409

FortiProxy did not support nested addrgrp definition, which caused a configuration error while upgrading.

929821

"Bad gateway" error message and httpsd process exits with segmentation fault when generating a TAC report from GUI.

927316

SNAT uses interface IP address instead of address from IP pool with forward server.

933030

Disable netflow and sflow commands which are not supported by FortiProxy.

933588

Build compile error during upgrade.

934498

When log-http-transaction is enabled, forward traffic to WAD only when UTM is enabled or the action of the policy is deny.

939241

939575

High CPU when DNS server is busy.

939160

WAD crash on traffic when VDOM is enabled and a global webfilter profile is attached to a policy.

935917

The respective corresponding sandbox should be displayed correctly.

936513

DNS is not updated with HA reserved mgmt interface..

Common vulnerabilities and exposures

FortiProxy 7.0.12 is no longer vulnerable to the following CVE reference. Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE reference

923315

CVE-2023-45583