Resolved issues
The resolved issues listed below may not list every bug that has been corrected with this release. For inquiries about a particular bug, please visit FortiCloud.
|
Bug ID |
Description |
|---|---|
|
927122 |
Client cert memory leak fix from FortiProxy. |
|
926668 |
Wad crash when trying to allocate a zero length object. |
|
925922 |
MySQL typo. |
|
925112 |
Port from FPX: EMS Cloud Fabric Connector not working. |
|
925675 |
Display create secret button in personal folder. |
|
924904 |
WinSCP video file deleted if user clicks reconnect when current connection closed. |
|
924771, 877090 |
Password changer crash. |
|
924185 |
`FortiProduct (SSH Key) ` passphrase field is password type. |
|
924967 |
wad crash when server side is disconnected |
|
921159 |
Format string bug in httpsd and cli - automation test. |
|
923591 |
Secret cannot be edited. |
|
877321 |
Secret upload improvement. |
|
922825 |
FortiPAM crashes when launching an associated secret to a Cisco server. |
|
918137 |
Improved user authentication log and replacement message page. |
|
923250 |
Refactor launch prompt error. |
|
923237 |
Remove none option in template permission. |
|
922963, 923131, 923599 |
Hide AV scan if no file launcher. |
|
924403 |
wad crash when SFTP/SMB authentication request is expired or manually modified. |
|
923988 |
Add upgrade function for alertemail mail to. |
|
924050 |
Change the default value of inherit-folder-ztna to disable to avoid configuration lost in upgrade. |
|
919761 |
Null pointer check to access permission table. |
|
920067, 917965 919085, 920170 918877, 921268, 922752 |
The user does not have permission to use email service and other GUI issues. |
|
922344 |
Folder permission validation. |
|
921938 |
Fix HA sync issue when user password policy is enabled. |
|
921071 |
SSH auto password delivery fails with server Cisco_7200. |
|
922584 |
Hide SSL_ERROR_SSL error messages from console. |
|
920106 |
LDAP/RADIUS 2FA authentication failure. |
|
921742 |
Format address array. |
|
920257 |
Use the original client IP for trusted host checking. |
|
920458 |
Bypass approval feature. |
|
920610, 0920637, 0919554 |
folder list clone update count. |
|
920506 |
WAD crash was observed. |
|
920208 |
Launching web account (FortiGate+DNS+FQDN) logs out the current user |
|
919596 |
In a folder with `Add Secret` and Secret `List` permission; clone a secret shows empty fields. |
|
897253 |
Automatically identify the correct remote server to authenticate a remote user. |
|
919179 |
Hide unnecessary service. |
|
919670 |
User info daemon crash. |
|
918890 |
In target-only, target-address field cannot be empty. |
|
918865 |
Request enforced for all secrets |
|
863569 |
Non-proxy PuTTy should be disabled when using an SSH key. |
|
920035 |
Invalid 'Approved Access' in secret. |
|
919135 |
WAD crash observed on CM build 0418. |
|
919133 |
miglogd crash observed on CM build 0418. |
|
896180 |
FortiPAM hardware license. |
|
918116, 919678 |
Provide an extra customized http header for extension to indicate video has finished. |
|
804808, 904559 |
Support totp in SSH authentication. |
|
884593, 0896564, 0890817, 0908686, 0884633 |
Optimize the navbar menu structure. |
|
915230 |
Add PAM disk conserve mode. |
|
918418 |
When installing FortiPAM for the first time, incorrect prompt when enabling email notification. |
|
918485 |
Allow % in secret url field. |
|
918346 |
Edit totp html. |
|
913663 |
Occasionally, server list is stuck unless refreshed. |
|
910784 |
Enable WebSMB service by default when creating a secret with template ' Unix Account (Web CIFS)'. |
|
917965 |
api-user cannot add a secret job. |
|
897541, 904137 |
Include email notification setting in the user wizard. |
|
881157 |
Add new radio for user defined role in the user wizard. |
|
882407 |
Job execution time display format issue. |
|
0899609 |
Add regex and logic options to automation-trigger. |
|
917750 |
Web app launching failure. |
|
887801, 896115 |
Secret request refactor for multiple requests in one email. |
|
914149 |
Add secret name on the title of edit page. |
|
877321 |
Update template in upload xlsm. |
|
887801, 908824 |
Add settings related to combine multiple requests into one email; support custom port for baseurl. |
|
913639 |
Add authentication failure prompt to Web SSH. |
|
886577, 0887801 |
Add user guide information for secret request email and vnc display number. |
|
914744 |
HA heartbeat port mimics admin access configuration of port1. |
|
887801 |
Combine multiple secret request notifications in one email to the approver. |
|
915069 |
Mask password on release build. |
|
899189 |
Display sudo disclaimer to user with SSH AUTO password. |
|
914654 |
Update secret wad cache when template gets updated. |
|
912655 |
PAM launching failure when NAT is in between. |
|
798866, 913635 |
Job list execution status. |
|
913523 |
Image restore from CLI failed when GUI pages are opened. |
|
911223 |
Provide download blocking replacement message page to users for file blocked by av/dlp. |
|
865654, 0885138, 0810687 |
Support AD restriction. |
|
911262 |
Hide DLP settings in secret when AVDB license expires. |
|
840512 |
Notify user when user number exceed licensed seats. |
|
904137 |
License expiration notification and restriction. |
|
903079 |
Enable editing the launcher for default secret templates. |
|
827628 |
Secret edits fail after cloning. |
|
908671, 912019 |
FortiPAM HTTP video storage backend refactor. |
|
908444 |
Allow creation of api-user with schedule. |
|
904438 |
Check secret duplication before clone. |
|
897591, 853452 |
Add CLI launchers. |
|
854712 |
Client software integrity check CLI support. |
|
902469 |
Support multiple requests |
|
899189 |
SSH auto password does not support sudo with disclaimer. |
|
860158 |
Support Logs of AV and DLP on GUI. |
|
905335 |
Support AntiVirus and DLP license validation check in the scan procedure of file transfer launchers. |
|
912775 |
Grey out non-editable DLP default sensors. |
|
914061 |
Missing DLP uploading file logs for |
|
845099 |
Add target only secret template. |
|
868233, 866748 |
Multiple file transfer launchers cannot be launched within a single browser at the same time. |
|
906492 |
Remove disclaimer failed login information. |
|
893740 |
Modify table size for a different platform. |
|
913687 |
User unable see secret when they do not have access to the template. |
|
864749 |
Allow owner to bypass secret approval process. |
|
814300 |
Improvements on user delete. |
|
822815 |
Provide a way to explicitly download a secret video from the log page. |
|
847167 |
Prohibit deleting a root personal folder from the GUI. |
|
874509 |
Add validators for checking ssh private and public key format. |
|
896096 |
Hide address types not needed when creating a new address or an address group. |
|
897188 |
Web Launcher restriction not working. |
|
906942 |
AWS account creation requires more validation. |
|
911230 |
Add file size unit for DLP large-file. |
|
910813 |
Multiple launchings with customized templates. |
|
910780 |
Unnecessary 'Launch' button. |
|
910297 |
Adding field type check for sensitive information field when switching templates. |
|
905935 |
wad crash is observed; wad_aio_module_close closes during stress. |
|
897304 |
Inherited folder permission should show up in details. |
|
849255 |
Template and database user filter. |
|
909683 |
Change all the FortiGate names in VMware ovf files. |
|
909693 |
If the first firewall policy is disabled, FortiPAM GUI becomes unavailable. |
|
848805 |
Display remaining time for approved requests. |
|
893730 |
SSH launching fails after password change for the SSH key using template with password and passphrase. |
|
910367 |
Optimize secret approval flag in the GUI API. |
|
829558 |
Add two buttons that could go to the secret /secret video log page with targeted Token ID. |
|
867911 |
Check RAID disk status every 5 minutes. |
|
909198 |
PuTTY SSH connecting failure with the FortiTester server. |
|
907267 |
Add a new parameter for the WinSCP launcher: |
|
894252 |
Add status column for the job listing page. |
|
851587 |
After running the |
|
909718 |
Format tje string bug in Fclicense daemon. |
|
910007 |
DLP profile is invisible to standard users. |
|
908190 |
Grey out the default password changers from the GUI. |
|
879947 |
WebSFTP and WebSMB cannot be controlled from Service Setting. |
|
909860 |
Failed to create a customized launcher. |
|
898516 |
Add the Hyper-V faceplate layout. |
|
872884 |
Application type in the log for WebSFTP and WebSMB is missing. |
|
865722, 863356 |
Add the certificate related attribute and test connection to server button. |
|
893484 |
After the factory reset, the GUI is not available from the default IP address. |
|
802577 |
Single concurrent session to logout from all wad workers. |
|
902540 |
The SSH logs page is showing previously displayed secret logs. |
|
907427 |
Upgrade liburing to latest release version 2.3. |
|
872589 |
Current system time is not correct when manually setting the time. |
|
907485 |
The FortiPAM HTTP module is unable to receive complete HTTP POST body from FortiClient's uploaded video. |
|
789786 |
Fatal error: unable to find "node_mod_common.h" during parallel build. |
|
900435 |
Unable to delete the last entry of IPv4 trusted hosts for the user. |
|
907101 |
Correct the typo in New user Definition(1.1). |
|
904443 |
Able to create identical folder in FortiPAM. |
|
906449 |
GUI stuck while opening a file with auto-password enabled. |
|
897542 |
Option to enable/disable the admin login disclaimer and modify the corresponding text. |
|
878078 |
Extesion Only: If launching a secret with Web SSH or Web FTP; only one session is recorded. |
|
877879 |
Update the secret name on the favorite menu after changing the secret name in the edit page. |
|
865931 |
LibGD to 2.3.3. |
|
906156 |
Failed to create a new user. |
|
905640 |
Enhance to forbid empty cluster password. |
|
905233 |
RDP connection failure on the hardware box when recording. |
|
865931 |
tcpdump vulnerabilities - precaution upgrade to 4.99.1. |
|
886975 |
Add ZTNA secret launch control on folder. |
|
894302 |
Separate settings for RADIUS/FAZ when using DR. |
|
879947 |
Add SFTP service control. |
|
897541 |
Include email notification setting in the user wizard. |
|
882636, 902400, 865931 |
Upgrade OpenSSL to 3.0.8. |
|
848549 |
Add a hint message for `Cisco Enable Secret` when no user secret is associated. |
|
848549 |
New everyone default user group. |
|
896750 |
Extend the shell prompt. |
|
878581 |
When the admin is under the glass breaking mode, request status is not correct after the admin approves the request. |
|
903204 |
Return the correct port media for FortiPAM3000G/1000G. |
|
874662 |
SSH procedure needs at least one 'expect' field to work. |
|
901345 |
When disabling the proxy mode on an SSH key secret, all the default launchers should be disabled. |
|
872781 |
New access control option for disabling the non-proxy mode. |
|
790421 |
VNC display variable support. |
|
879582 |
When the FortiPAM feature is disabled in the EMS, the GUI should display an error message. |
|
862589 |
Invalid alarm for a secret launching from a non-certificate client. |
|
865453 |
When failed to connect to FortiClient; no prompt on Chrome. |
|
861389 |
When there is no ForitClient and the user tries to launch the native launcher; should report an error. |
|
860158 |
Support logs for AV and DLP on the GUI. |
|
863268 |
Support DLP configuration on the GUI. |
|
886975 |
Add "device control by ZTNA Tag" for folders. |
|
902676 |
WAD SSH proxy could not connect to the Cisco router with KEX "diffie-hellman-group-exchange-sha1" + cipher "aes192-cbc". |
|
893026 |
Timestamp of log when it is in DST. |
|
865931 |
Use the correct package signatures. |
|
817957 |
Update log summary time frame to 7 days. |
|
892493 |
Change the faceplate port type to fiber to fit the appearance. |
|
867443 |
Send test emails. |
|
899908 |
Show "warning" or "disclaimer" when the admin logins to the interface IP address. |
|
901484 |
Edge case for secret editing. |
|
897253 |
Remove auto add LDAP/RADIUS server into the default authentication scheme database. |
|
896177 |
Add FortiPAM upgrade code (template srv-info). |
|
865931 |
Upgrade the KRB5 version to 1.19.4. |
|
868811 |
Remove the downgrade configuration migration function. |
|
865931 |
Upgrade sqlite version to 3.39.2. |
|
849255 |
Template permission control. |
|
810799 |
RDP restricted admin mode cannot auto log in to Windows 10/11. |
|
865931 |
Upgrade curl to 7.86. |
|
865722, 863851 |
Add certificate validation to automatic backup. |
|
901632 |
Accept FortiPAM 1.0.x HA member if HA group passwd is empty. |
|
842754, 899220 |
ZTNA layout enhancement. |
|
865931 |
Upgrade OpenLDAP version to 2.6.3. |
|
893198 |
New SecureCRT launcher. |
|
858229, 832286 |
Only display the entry of public folder list and personal folder; routing enhancement. |
|
865313, 882312 |
Delete 'SSH Auto-Password' tooltips and delete the job page web API text. |
|
882077 |
Change FortiGate to FortiPAM on VMware ovf files. |
|
884542 |
Adding the network diagnose tools support. |
|
893123 |
FortiPAM 1000G/ 3000G: No disk information, disk health, disk attributes, and disk errors commands on FortiPAM OS. |
|
863354 |
Add port option to the backup server. |
|
880074 |
When creating a new role, present the standard user's setting. |
|
883168 |
Enhancement for Secret List view. |
|
891436 |
Secret search under associated secret does not work. |
|
890272 |
Enhancement on managing auto password changing. |
|
893913 |
View button disappears for credential history. |
|
845705 |
Allow launching secrets when admin is in the glass breaking mode. |
|
879947 |
Add SFTP service setting. |
|
863198 |
Update secret verification status after verification. |
|
845087 |
Edit View tabs: Place actions above tabs. |
|
891441 |
Add secret policy clone functionality. |
|
805806 |
Syntax limitation: The format of [Variable] or Variable# is not allowed. |
|
865012 |
Remove web launchers from the launcher type drowdown. |
|
896180 |
Hardcode initial seats to 1000G/3000G. |
|
889961 |
Support GPT partitions and EXT4 file systems for KVM and VMware platforms. |
|
893356 |
Update API version to match the firmware version. |
|
849255 |
Support template clone and add permission flag for template response. |
|
892493 |
Rearrange port to fit machine appearance. |
|
884631 |
Rename 'Launch Device Control' to 'ZTNA Control'. |
|
883808, 868242 |
FortiPAM 1000G/3000G hardware RAID CLI |
|
896615 |
Fix FortiToken cloud issue on manually inputting a wrong token. |
|
876725, 840559 |
Escape special characters in navigation URL. |
|
883477 |
Use reply-to email as sender address. |
|
871639 |
Support FortiToken mobile push configured on the FortiAuthenticator side. |
|
893897 |
Change password visibility process. |
|
893696 |
SSH auto password does not work when both key and password exist for a secret without an associated secret. |
|
883565 |
Command log shows the wrong Login user for Web SSH. |
|
877090 |
Moving multiple secrets and give the option of displaying failed secrets. |
|
849255 |
Template permission support. |
|
877321 |
Improve upload procedure to support other templates. |
|
876120 |
Add commands for web launcher proxy (web-authentication). |
|
891441 |
Add clone flag to secret policy. |
|
841234 |
Limit the number of characters in name and email fields to 64. |
|
874658 |
Prevent job new-line from reverting to the default password changer. |
|
889961 |
Support GPT partitions and EXT4 file systems for KVM and VMware platforms. |
|
894051 |
Adjust the secret list API handler so the GUI does not fail. |
|
865731 |
Set maximum body size for the internal API. |
|
891001 |
Authentication configuration mandatory field need to be highlighted. |
|
877131 |
Secret creation/cloning attribute not maintained. |
|
817710 |
GUI should show the full log message and would be better if the log messages only show changed configurations. |
|
890376 |
Web SSH crashes when using associated secret authentication. |
|
889900 |
SSH secret with PuTTY launcher in the proxy mode fails when authenticated with an associate secret. |
|
872781 |
New access control option for disabling the non-proxy mode. |
|
888479 |
Fix the secret UUID in the log. |
|
891206 |
Remove the domain field in the login page when SAML is not configured. |
|
884995 |
Rename 'Edit Secret' and 'Undo Changes'. |
|
890568 |
Delete the 16-bit option recording color depth. |
|
827547 |
When launching on the Cisco OS with Web SSH, the behavior of 'space' and '?' in keyboard are different with normal PuTTY or console. |
|
818585 |
Web SSH cursor issues. |
|
891437 |
Web SSH cursor is not at the correct position. |
|
865237 |
The Launch Secret button and the |
|
875742 |
Information error for Web SSH/RDP/VNC. |
|
883168, 876986, 877093 |
Secret list improvements. |
|
860209 |
Wad trace GUI API support. |
|
863356 |
Send test backup function to apache. |
|
872633 |
Upgrade libssh2 to project trunk build. |
|
876120, 869866 |
Web proxy keywords table. |
|
885478 |
Revise layout in secret field so it is easier to edit. |
|
873888 |
User with view permission to a secret with the 'View Encrypted information' role should be able to view secret password and key. |
|
813008 |
New Secret > Allow for template switching without field conversion slide. |
|
876629 |
SSH filter issues. |
|
845705 |
Allow glass breaking user to launch any secret. |
|
859888, 876121 |
Restrict the user from upgrading the account profile to a permission higher than they have. |
|
864930 |
Prevent cmdb from adding a concurrent request. |
|
875356 |
Allow check-out after check-in. |
|
878496 |
Support right click to disable/enable a user. |
|
879947 |
WebSFTP and WebSMB cannot be controlled from Service Setting. |
|
882360 |
Password policy should not be available when the password changer type is 'SSH with Public Key'. |
|
867177 |
Hide the Expires column by default in Monitor > Active Sessions. |
|
867443 |
Add test email function to FortiPAM. |
|
885138 |
Prevent blocklist and allowlist from being set at the same time. |
|
865931 |
Port FortiOS ECO 218884: Openssl 3.0. |
|
868521 |
When creating or cloning a launcher, 'File Launcher' setting is not available on the GUI. |
|
877002 |
Add FQDN information in email notifications. |
|
790421 |
VNC dsplay variable support. |
|
810687 |
Add blocklist/allowlist to GUI API. |
|
865012 |
Prevent user from setting up a web-app launcher to non-default launcher. |
|
877355 |
Dynamic FQDN sometimes does not work for Web RDP. |
|
877460 |
Enable SMS option in the user wizard. |
|
870808 |
AV Profile not loading value. |
|
879074 |
Wad crash when no passphrase field in the template. |
|
874851 |
CLI does not show the FortiClient EMS endpoint in the available options to configure. Also, the CLI is missing 'autocomplete' for the feature. |
|
862156 |
Change permission for the RADIUS test connection. |
Common Vulnerabilities and Exposures
|
Bug ID |
CVE references |
|---|---|
|
912019 |
FortiPAM 1.1.0 is no longer vulnerable to the following CVE-Reference(s):
|
|
919845 |
FortiPAM 1.1.0 is no longer vulnerable to the following CVE-Reference(s):
|
Visit https://fortiguard.com/psirt for more information.