Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.4.0. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID

Description

772418

Fix ICAP client not forwarding response when host matches FQDN.

834299

SSH command filter no longer works after prompt change.

868879

No valid FortiSandbox Cloud license while enabling Cloud Sandbox.

870099

LDAP cache was not updated properly after the user group changed in Active Directory server.

876758

SSH public keys are lost after upgrading from Beta 1 to latest interim build, and they can no longer be configured.

883131

Correlation log does not show security action when application category is unknown.

885552

Fix matching regression caused by secure web proxy .

887742

Config backup encryption key should not appear in GET parameters.

892116

Issue with the WAD debug filter on vd_id and dst6 or src6.

905188

Unexpect hang-up on FPX-4000E.

906862

FortiProxy ESXi VM reboots randomly.

908697

FortiNBI reports error: Failed to change FPX add mode because the FNBI service is stopped.

909271

Authenticated users using an IP-based authentication rule may need to be re-authenticated per request.

909286, 931372

Fix WAD crash seen due to missing hash map initialization and port.

910978

FortiNBI does not support PAC file and does not work using manually configuration.

913013

Update voltage monitoring with official Supermicro values.

914533

FortiGate DLP filter EXE files does not work on Windows.

917330

Some non-http traffic was redirected to WAD unexpectedly when L7 address exists in policy.

917412

FPX-2000G and FPX-4000G STA and UID LED color issue.

919463

FortiProxy kernel memory leak.

920083

EIP of mgmt-intf is mistakenly moved from secondary FPX to the primary in an AWS A-P HA cluster.

921158

Issue with format string that causes httpsd and CLI crash.

921902

LDAP search type default is unset due to an incorrect default value.

922092

WAD debug settings do not show the correct category.

923302

Tencent WeCom cannot send picture through web explicit proxy.

923468

Unable to config wildcard FQDN addresses in the GUI.

924586

FortiProxy HA config-sync-only secondaries receive system updates triggered by both updated and hasync.

924740

Need to verify filters of wad debug trace and make sure all the necessary info is logged and filter works properly.

924886, 931091

Fix the proxy-based address is not allowed for access-proxy proxy-policy.

924919

Explicit FTPS authentication with transparent policy does not work.

926491

WAD policy matching crashed at matching the source address due to null source and destination addresses in dummy policy.

927004

Validate address group members when config is loaded. If an error occurs while loading iptables rules for a specific policy, skip only the malformed policy instead of aborting the policy loading as a whole.

927838

FortiProxy matches user to wrong user group and hits the wrong policy.

928710

External resource entry missing under destination address in firewall policy.

928979

When multiple ports are configured for a firewall policy's service, only traffic to the first port matches the policy.

929232

Non-root VDOM explicit proxy DNS fails.

929971

Fix scanunit error logs on non-error case.

930060

Inline option for FortiSandbox inspection is missing in FPX antivirus profile.

931068

Sessions pane does not show any data in FortiView ZTNA Servers by Bytes

931312

Local traffic section should be removed as FortiProxy does not support local-in policy.

931507

Change FortiCloud Logs to FortiGate Cloud.

931778

Fix HTTP request to FQDN address not directed to WAN when dst_address includes wildcard FQDN.

932335

Cloud FortiSandbox is shown instead of FortiCloud Logs/FortiGate Cloud.

932487

WAD worker memory usage slowly increased.

932620

GUI does not display Log HTTP Transaction under ZTNA Rules.

932623

Add device info columns (clientdeviceid, clientdeviceowner, clientdevicetags, emsconnection) to the http-transaction log.

932736

When executing the get sys ha status command, the CLI session crashed.

932892

internet-service6 is not displayed properly in a policy.

933788

srcaddr6 should not be configurable on a policy when internet-service is enabled.

933902

Unable to save interfaces when configuring a fabric connector.

933905

Revert to the newer version of json parse/print needed for FNBI.

934219

WAD crashes at wad_url_fetch_cate2.

934376

CSF GUI API forwarding fails.

934392

Support missing nested address group members.

934405

The visibility field is missing in the service custom.

934816

A-P cluster fails to form properly after a switchover, requiring a reboot on the new secondary device.

934833

Fix a bug preventing Chrome from installing the FNBI extension.

Common vulnerabilities and exposures

FortiProxy 7.4.0 is no longer vulnerable to the following CVE reference. Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE reference

865929

CVE-2022-45862

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.4.0. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID

Description

772418

Fix ICAP client not forwarding response when host matches FQDN.

834299

SSH command filter no longer works after prompt change.

868879

No valid FortiSandbox Cloud license while enabling Cloud Sandbox.

870099

LDAP cache was not updated properly after the user group changed in Active Directory server.

876758

SSH public keys are lost after upgrading from Beta 1 to latest interim build, and they can no longer be configured.

883131

Correlation log does not show security action when application category is unknown.

885552

Fix matching regression caused by secure web proxy .

887742

Config backup encryption key should not appear in GET parameters.

892116

Issue with the WAD debug filter on vd_id and dst6 or src6.

905188

Unexpect hang-up on FPX-4000E.

906862

FortiProxy ESXi VM reboots randomly.

908697

FortiNBI reports error: Failed to change FPX add mode because the FNBI service is stopped.

909271

Authenticated users using an IP-based authentication rule may need to be re-authenticated per request.

909286, 931372

Fix WAD crash seen due to missing hash map initialization and port.

910978

FortiNBI does not support PAC file and does not work using manually configuration.

913013

Update voltage monitoring with official Supermicro values.

914533

FortiGate DLP filter EXE files does not work on Windows.

917330

Some non-http traffic was redirected to WAD unexpectedly when L7 address exists in policy.

917412

FPX-2000G and FPX-4000G STA and UID LED color issue.

919463

FortiProxy kernel memory leak.

920083

EIP of mgmt-intf is mistakenly moved from secondary FPX to the primary in an AWS A-P HA cluster.

921158

Issue with format string that causes httpsd and CLI crash.

921902

LDAP search type default is unset due to an incorrect default value.

922092

WAD debug settings do not show the correct category.

923302

Tencent WeCom cannot send picture through web explicit proxy.

923468

Unable to config wildcard FQDN addresses in the GUI.

924586

FortiProxy HA config-sync-only secondaries receive system updates triggered by both updated and hasync.

924740

Need to verify filters of wad debug trace and make sure all the necessary info is logged and filter works properly.

924886, 931091

Fix the proxy-based address is not allowed for access-proxy proxy-policy.

924919

Explicit FTPS authentication with transparent policy does not work.

926491

WAD policy matching crashed at matching the source address due to null source and destination addresses in dummy policy.

927004

Validate address group members when config is loaded. If an error occurs while loading iptables rules for a specific policy, skip only the malformed policy instead of aborting the policy loading as a whole.

927838

FortiProxy matches user to wrong user group and hits the wrong policy.

928710

External resource entry missing under destination address in firewall policy.

928979

When multiple ports are configured for a firewall policy's service, only traffic to the first port matches the policy.

929232

Non-root VDOM explicit proxy DNS fails.

929971

Fix scanunit error logs on non-error case.

930060

Inline option for FortiSandbox inspection is missing in FPX antivirus profile.

931068

Sessions pane does not show any data in FortiView ZTNA Servers by Bytes

931312

Local traffic section should be removed as FortiProxy does not support local-in policy.

931507

Change FortiCloud Logs to FortiGate Cloud.

931778

Fix HTTP request to FQDN address not directed to WAN when dst_address includes wildcard FQDN.

932335

Cloud FortiSandbox is shown instead of FortiCloud Logs/FortiGate Cloud.

932487

WAD worker memory usage slowly increased.

932620

GUI does not display Log HTTP Transaction under ZTNA Rules.

932623

Add device info columns (clientdeviceid, clientdeviceowner, clientdevicetags, emsconnection) to the http-transaction log.

932736

When executing the get sys ha status command, the CLI session crashed.

932892

internet-service6 is not displayed properly in a policy.

933788

srcaddr6 should not be configurable on a policy when internet-service is enabled.

933902

Unable to save interfaces when configuring a fabric connector.

933905

Revert to the newer version of json parse/print needed for FNBI.

934219

WAD crashes at wad_url_fetch_cate2.

934376

CSF GUI API forwarding fails.

934392

Support missing nested address group members.

934405

The visibility field is missing in the service custom.

934816

A-P cluster fails to form properly after a switchover, requiring a reboot on the new secondary device.

934833

Fix a bug preventing Chrome from installing the FNBI extension.

Common vulnerabilities and exposures

FortiProxy 7.4.0 is no longer vulnerable to the following CVE reference. Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE reference

865929

CVE-2022-45862