Resolved issues
The following issues have been fixed in FortiProxy 7.2.2. For inquiries about a particular bug, please contact Customer Service & Support.
Bug ID |
Description |
---|---|
550701 |
Fix signal 6 backtrace is not generated for forticron daemon. |
553604 |
CMDB lock issues. |
713286 |
WAD crash at signal 11 on video filter related process. |
742483 |
Fix random system events log with the message "msg=UrlBwl-black gzopen fail". |
764770 |
Fix external resource download DNS bottleneck. |
784326 |
Flaws in auth_key_encrypt. |
784785 |
Unsupported ZTNA logic prevents proper ZTNA matching. Fix default CA certificate changed to blank after refresh. |
789153 |
A profile with higher privileges than the user's own profile can be set. |
793651, 798873, 814265, 831805, 834375, 836260, 842082, 849803, 851521, 856031, 858061, 859390, 859420, 862510, 863235, 863428, 866845, 867418 |
Fix GUI issues. |
807982 |
Disable group profile with DNS filter in explicit-web policy. |
809141 |
Client hung when FortiAI error encountered with fortiai-error-action as log-only in antivirus profile. |
810989 |
GUI permission override should only apply to GET by default. |
814038 |
Fix VDOM data from leaking to other VDOMs through the REST API (Report Runner and CMDB tables cluster-sync and vdom-property). |
818371 |
Fix WAD process crash at wad_http_req_add_option of wad_http_engine. |
818869 |
FTP traffic does not get redirected to WAD. |
819887 |
GCP does not process multipart MIME data. |
823078, 855664, 855853 |
WAD user-info process randomly consumes 100% CPU of one core. |
826254 |
Fix disk formatting issue after changing usage. |
830450 |
WAD crashes on wad_p2s_ciphers_filter. |
832515, 834314 |
Crash due to connection aborting. |
834378 |
Guest users able to access webpage past the provisioned time allotted for them. |
834420, 834729 |
Extra, unnecessary X-authentication-User/Group field on ICAP header and default ICAP header change |
835129 |
ICAP client header parser cannot handle piggy or sibling flag HTTP headers. |
837192 |
Fix virtual MAC setup in HA mode. |
838913 |
Fix malformed request false positive issue. |
839201 |
ICAP client timeout issue . |
840549 |
Fix WAD unable to recognize RSSO user. |
841506 |
Fix WAD memory spike on ISO file when stream-scan enabled. |
841571 |
Disable VXLAN configuration in transparent mode. |
841828 |
Traffic is not authorized when AD username is provided without a domain. |
842764, 845323 |
Update of VRF with multiple VDOMs. |
844990 |
Enforce IP bans on existing traffic. |
845570 |
Fix for re-compiling |
845577 |
WAD crashes at fts_client_hello_cancel. |
845818 |
Remove the 10 second count down for falling back URL when SSO IdP is not configured. |
846630 |
ZTNA status removed from GUI. |
846857 |
Fix TLS 1.1 certificate-inspection bypass failure. |
846870 |
Allow management access to local interfaces with IPsec and SSLVPN. |
847484 |
Read-only administrators able to sniff other administrators' cookies. |
849320 |
Improve performance when changing the configuration. |
849549 |
In deep-inspection, FortiProxy cannot forward ALPN extension in clienthello to server. |
849714 |
Keep the default value, |
850440 |
Fix WAD algorithm crash when loading ia-profile. |
850558 |
Webcache is unable to retrieve large cached objects. |
850841 |
Arbitrary read/write vulnerability in custom language. |
851134 |
Change the maximum size allowed for entry names under |
851188 |
Fix string comparing issue when the host name in the request is capitalized. |
851508 |
FNBI installation failed on version 7.2.1. |
851602 |
FTP over HTTP connect method should not require that ftp-over-http be enabled. Port matching mechanism optimized. Missing semicolon caused a compile error. |
852198 |
Saving issue when adding entries to an Isolator profile. |
852416 |
Trusted host IP table rules are only generated for super administrators. |
852416 |
Non-super administrators are skipped when checking for trusthost wildcards. |
852875 |
WAD memory is not assigned when building JSON responses for isolator. |
853406 |
Fix SSL certificate full check for external resources when the hostname is the IP address. |
854176 |
Patch for arbitrary file deletion in log reports. |
854432 |
Fix TCP port validate return false for proxy SSL redirect. |
854469 |
Fix print mgmt-data syntax errors. |
854833 |
Fix incorrect license information on secondary FortiProxy. |
855009 |
Fix error when adding different URL lists to different URL match ruless. |
855603 |
Fix pipeline requests failure when enabling IPS/APPCTL. |
855816 |
Clone DSCP marker to the other end of transparent proxies. |
855838 |
High latency and CPU usage when deleting webcache entries matching a simple-string URL pattern. |
856008 |
Fix netlink socket not closed when setting up IP pools. |
856235 |
High memory usage by WAD worker in object ssl.fts.str.fstr_buffer_bytes. |
857284 |
Remove NAF. |
857338 |
Fix WAD traffic stats client add stats crash. |
857507 |
WAD crash at |
857530 |
The image-analyzer profile should be a per VDOM configuration, not a global shared profile, |
857691 |
Remove duplicate |
858488 |
Fix wa_cs daemon crashes when the request data length is larger than the range data length. |
858647 |
Fix race condition resulting in interfaces being stuck up or down with HA enabled . |
858936 |
Proxy address cannot be selected when editing an isolator profile. |
859937 |
Fix webcache memory leak. |
860381 |
Fix webcache prefetch build crashes when an entry has an empty configuration. |
860461 |
Fix wrong web proxy profile assignment issue. |
860495 |
Decode DLP log URL field to utf-8. |
860520 |
Improve table build speed when policy uses a zone as the soure and/or destination address. |
860620 |
Potential memory leak on DoT traffic. |
861151 |
SSL Mirror does not work. |
862001 |
Prevent password ciphertext exposure in logs. |
862130 |
Fix high data/partition usage. |
862846 |
Configuration Backup and Restore in CLI is not working as expected. The |
864621 |
SSH public key changes after every reboot |
865135 |
Multipart boundary parsing failed with CRLF before the end of boundary1. |
865318 |
ICAP server with antivirus crash when sending HTTPS to eicar.com . |
868043 |
WAD worker crashes when performing basic local authentication. |
Common vulnerabilities and exposures
FortiProxy 7.2.2 is no longer vulnerable to the following CVE references. Visit https://fortiguard.com/psirt for more information.
Bug ID |
CVE reference |
---|---|
854181 |
|
854229 |
|
866003 |
|
845849 |
|
862003 |
|
862001 |
|
854176 |
|
847484 |
|
862001 |
|
864621 |