Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The resolved issues listed below may not list every bug that has been corrected with this release. For inquiries about a particular bug, please visit FortiCloud.

Bug ID

Description

927122

Client cert memory leak fix from FortiProxy.

926668

Wad crash when trying to allocate a zero length object.

925922

MySQL typo.

925112

Port from FPX: EMS Cloud Fabric Connector not working.

925675

Display create secret button in personal folder.

924904

WinSCP video file deleted if user clicks reconnect when current connection closed.

924771, 877090

Password changer crash.

924185

`FortiProduct (SSH Key) ` passphrase field is password type.

924967

wad crash when server side is disconnected

921159

Format string bug in httpsd and cli - automation test.

923591

Secret cannot be edited.

877321

Secret upload improvement.

922825

FortiPAM crashes when launching an associated secret to a Cisco server.

918137

Improved user authentication log and replacement message page.

923250

Refactor launch prompt error.

923237

Remove none option in template permission.

922963, 923131, 923599

Hide AV scan if no file launcher.

924403

wad crash when SFTP/SMB authentication request is expired or manually modified.

923988

Add upgrade function for alertemail mail to.

924050

Change the default value of inherit-folder-ztna to disable to avoid configuration lost in upgrade.

919761

Null pointer check to access permission table.

920067, 917965 919085, 920170 918877, 921268, 922752

The user does not have permission to use email service and other GUI issues.

922344

Folder permission validation.

921938

Fix HA sync issue when user password policy is enabled.

921071

SSH auto password delivery fails with server Cisco_7200.

922584

Hide SSL_ERROR_SSL error messages from console.

920106

LDAP/RADIUS 2FA authentication failure.

921742

Format address array.

920257

Use the original client IP for trusted host checking.

920458

Bypass approval feature.

920610, 0920637, 0919554

folder list clone update count.

920506

WAD crash was observed.

920208

Launching web account (FortiGate+DNS+FQDN) logs out the current user

919596

In a folder with `Add Secret` and Secret `List` permission; clone a secret shows empty fields.

897253

Automatically identify the correct remote server to authenticate a remote user.

919179

Hide unnecessary service.

919670

User info daemon crash.

918890

In target-only, target-address field cannot be empty.

918865

Request enforced for all secrets

863569

Non-proxy PuTTy should be disabled when using an SSH key.

920035

Invalid 'Approved Access' in secret.

919135

WAD crash observed on CM build 0418.

919133

miglogd crash observed on CM build 0418.

896180

FortiPAM hardware license.

918116, 919678

Provide an extra customized http header for extension to indicate video has finished.

804808, 904559

Support totp in SSH authentication.

884593, 0896564, 0890817, 0908686, 0884633

Optimize the navbar menu structure.

915230

Add PAM disk conserve mode.

918418

When installing FortiPAM for the first time, incorrect prompt when enabling email notification.

918485

Allow % in secret url field.

918346

Edit totp html.

913663

Occasionally, server list is stuck unless refreshed.

910784

Enable WebSMB service by default when creating a secret with template ' Unix Account (Web CIFS)'.

917965

api-user cannot add a secret job.

897541, 904137

Include email notification setting in the user wizard.

881157

Add new radio for user defined role in the user wizard.

882407

Job execution time display format issue.

0899609

Add regex and logic options to automation-trigger.

917750

Web app launching failure.

887801, 896115

Secret request refactor for multiple requests in one email.

914149

Add secret name on the title of edit page.

877321

Update template in upload xlsm.

887801, 908824

Add settings related to combine multiple requests into one email; support custom port for baseurl.

913639

Add authentication failure prompt to Web SSH.

886577, 0887801

Add user guide information for secret request email and vnc display number.

914744

HA heartbeat port mimics admin access configuration of port1.

887801

Combine multiple secret request notifications in one email to the approver.

915069

Mask password on release build.

899189

Display sudo disclaimer to user with SSH AUTO password.

914654

Update secret wad cache when template gets updated.

912655

PAM launching failure when NAT is in between.

798866, 913635

Job list execution status.

913523

Image restore from CLI failed when GUI pages are opened.

911223

Provide download blocking replacement message page to users for file blocked by av/dlp.

865654, 0885138, 0810687

Support AD restriction.

911262

Hide DLP settings in secret when AVDB license expires.

840512

Notify user when user number exceed licensed seats.

904137

License expiration notification and restriction.

903079

Enable editing the launcher for default secret templates.

827628

Secret edits fail after cloning.

908671, 912019

FortiPAM HTTP video storage backend refactor.

908444

Allow creation of api-user with schedule.

904438

Check secret duplication before clone.

897591, 853452

Add CLI launchers.

854712

Client software integrity check CLI support.

902469

Support multiple requests

899189

SSH auto password does not support sudo with disclaimer.

860158

Support Logs of AV and DLP on GUI.

905335

Support AntiVirus and DLP license validation check in the scan procedure of file transfer launchers.

912775

Grey out non-editable DLP default sensors.

914061

Missing DLP uploading file logs for Content_Archive and Content_Summary when launching WebSFTP and WebSMB.

845099

Add target only secret template.

868233, 866748

Multiple file transfer launchers cannot be launched within a single browser at the same time.

906492

Remove disclaimer failed login information.

893740

Modify table size for a different platform.

913687

User unable see secret when they do not have access to the template.

864749

Allow owner to bypass secret approval process.

814300

Improvements on user delete.

822815

Provide a way to explicitly download a secret video from the log page.

847167

Prohibit deleting a root personal folder from the GUI.

874509

Add validators for checking ssh private and public key format.

896096

Hide address types not needed when creating a new address or an address group.

897188

Web Launcher restriction not working.

906942

AWS account creation requires more validation.

911230

Add file size unit for DLP large-file.

910813

Multiple launchings with customized templates.

910780

Unnecessary 'Launch' button.

910297

Adding field type check for sensitive information field when switching templates.

905935

wad crash is observed; wad_aio_module_close closes during stress.

897304

Inherited folder permission should show up in details.

849255

Template and database user filter.

909683

Change all the FortiGate names in VMware ovf files.

909693

If the first firewall policy is disabled, FortiPAM GUI becomes unavailable.

848805

Display remaining time for approved requests.

893730

SSH launching fails after password change for the SSH key using template with password and passphrase.

910367

Optimize secret approval flag in the GUI API.

829558

Add two buttons that could go to the secret /secret video log page with targeted Token ID.

867911

Check RAID disk status every 5 minutes.

909198

PuTTY SSH connecting failure with the FortiTester server.

907267

Add a new parameter for the WinSCP launcher: /newinstance.

894252

Add status column for the job listing page.

851587

After running the execute shutdown CLI command on FortiPAM 3000G, it does not powered off and its console still echoes the received characters even after being halted.

909718

Format tje string bug in Fclicense daemon.

910007

DLP profile is invisible to standard users.

908190

Grey out the default password changers from the GUI.

879947

WebSFTP and WebSMB cannot be controlled from Service Setting.

909860

Failed to create a customized launcher.

898516

Add the Hyper-V faceplate layout.

872884

Application type in the log for WebSFTP and WebSMB is missing.

865722, 863356

Add the certificate related attribute and test connection to server button.

893484

After the factory reset, the GUI is not available from the default IP address.

802577

Single concurrent session to logout from all wad workers.

902540

The SSH logs page is showing previously displayed secret logs.

907427

Upgrade liburing to latest release version 2.3.

872589

Current system time is not correct when manually setting the time.

907485

The FortiPAM HTTP module is unable to receive complete HTTP POST body from FortiClient's uploaded video.

789786

Fatal error: unable to find "node_mod_common.h" during parallel build.

900435

Unable to delete the last entry of IPv4 trusted hosts for the user.

907101

Correct the typo in New user Definition(1.1).

904443

Able to create identical folder in FortiPAM.

906449

GUI stuck while opening a file with auto-password enabled.

897542

Option to enable/disable the admin login disclaimer and modify the corresponding text.

878078

Extesion Only: If launching a secret with Web SSH or Web FTP; only one session is recorded.

877879

Update the secret name on the favorite menu after changing the secret name in the edit page.

865931

LibGD to 2.3.3.

906156

Failed to create a new user.

905640

Enhance to forbid empty cluster password.

905233

RDP connection failure on the hardware box when recording.

865931

tcpdump vulnerabilities - precaution upgrade to 4.99.1.

886975

Add ZTNA secret launch control on folder.

894302

Separate settings for RADIUS/FAZ when using DR.

879947

Add SFTP service control.

897541

Include email notification setting in the user wizard.

882636, 902400, 865931

Upgrade OpenSSL to 3.0.8.

848549

Add a hint message for `Cisco Enable Secret` when no user secret is associated.

848549

New everyone default user group.

896750

Extend the shell prompt.

878581

When the admin is under the glass breaking mode, request status is not correct after the admin approves the request.

903204

Return the correct port media for FortiPAM3000G/1000G.

874662

SSH procedure needs at least one 'expect' field to work.

901345

When disabling the proxy mode on an SSH key secret, all the default launchers should be disabled.

872781

New access control option for disabling the non-proxy mode.

790421

VNC display variable support.

879582

When the FortiPAM feature is disabled in the EMS, the GUI should display an error message.

862589

Invalid alarm for a secret launching from a non-certificate client.

865453

When failed to connect to FortiClient; no prompt on Chrome.

861389

When there is no ForitClient and the user tries to launch the native launcher; should report an error.

860158

Support logs for AV and DLP on the GUI.

863268

Support DLP configuration on the GUI.

886975

Add "device control by ZTNA Tag" for folders.

902676

WAD SSH proxy could not connect to the Cisco router with KEX "diffie-hellman-group-exchange-sha1" + cipher "aes192-cbc".

893026

Timestamp of log when it is in DST.

865931

Use the correct package signatures.

817957

Update log summary time frame to 7 days.

892493

Change the faceplate port type to fiber to fit the appearance.

867443

Send test emails.

899908

Show "warning" or "disclaimer" when the admin logins to the interface IP address.

901484

Edge case for secret editing.

897253

Remove auto add LDAP/RADIUS server into the default authentication scheme database.

896177

Add FortiPAM upgrade code (template srv-info).

865931

Upgrade the KRB5 version to 1.19.4.

868811

Remove the downgrade configuration migration function.

865931

Upgrade sqlite version to 3.39.2.

849255

Template permission control.

810799

RDP restricted admin mode cannot auto log in to Windows 10/11.

865931

Upgrade curl to 7.86.

865722, 863851

Add certificate validation to automatic backup.

901632

Accept FortiPAM 1.0.x HA member if HA group passwd is empty.

842754, 899220

ZTNA layout enhancement.

865931

Upgrade OpenLDAP version to 2.6.3.

893198

New SecureCRT launcher.

858229, 832286

Only display the entry of public folder list and personal folder; routing enhancement.

865313, 882312

Delete 'SSH Auto-Password' tooltips and delete the job page web API text.

882077

Change FortiGate to FortiPAM on VMware ovf files.

884542

Adding the network diagnose tools support.

893123

FortiPAM 1000G/ 3000G: No disk information, disk health, disk attributes, and disk errors commands on FortiPAM OS.

863354

Add port option to the backup server.

880074

When creating a new role, present the standard user's setting.

883168

Enhancement for Secret List view.

891436

Secret search under associated secret does not work.

890272

Enhancement on managing auto password changing.

893913

View button disappears for credential history.

845705

Allow launching secrets when admin is in the glass breaking mode.

879947

Add SFTP service setting.

863198

Update secret verification status after verification.

845087

Edit View tabs: Place actions above tabs.

891441

Add secret policy clone functionality.

805806

Syntax limitation: The format of [Variable] or Variable# is not allowed.

865012

Remove web launchers from the launcher type drowdown.

896180

Hardcode initial seats to 1000G/3000G.

889961

Support GPT partitions and EXT4 file systems for KVM and VMware platforms.

893356

Update API version to match the firmware version.

849255

Support template clone and add permission flag for template response.

892493

Rearrange port to fit machine appearance.

884631

Rename 'Launch Device Control' to 'ZTNA Control'.

883808, 868242

FortiPAM 1000G/3000G hardware RAID CLI execute raid create-and-format and diagnose system raid status commands.

896615

Fix FortiToken cloud issue on manually inputting a wrong token.

876725, 840559

Escape special characters in navigation URL.

883477

Use reply-to email as sender address.

871639

Support FortiToken mobile push configured on the FortiAuthenticator side.

893897

Change password visibility process.

893696

SSH auto password does not work when both key and password exist for a secret without an associated secret.

883565

Command log shows the wrong Login user for Web SSH.

877090

Moving multiple secrets and give the option of displaying failed secrets.

849255

Template permission support.

877321

Improve upload procedure to support other templates.

876120

Add commands for web launcher proxy (web-authentication).

891441

Add clone flag to secret policy.

841234

Limit the number of characters in name and email fields to 64.

874658

Prevent job new-line from reverting to the default password changer.

889961

Support GPT partitions and EXT4 file systems for KVM and VMware platforms.

894051

Adjust the secret list API handler so the GUI does not fail.

865731

Set maximum body size for the internal API.

891001

Authentication configuration mandatory field need to be highlighted.

877131

Secret creation/cloning attribute not maintained.

817710

GUI should show the full log message and would be better if the log messages only show changed configurations.

890376

Web SSH crashes when using associated secret authentication.

889900

SSH secret with PuTTY launcher in the proxy mode fails when authenticated with an associate secret.

872781

New access control option for disabling the non-proxy mode.

888479

Fix the secret UUID in the log.

891206

Remove the domain field in the login page when SAML is not configured.

884995

Rename 'Edit Secret' and 'Undo Changes'.

890568

Delete the 16-bit option recording color depth.

827547

When launching on the Cisco OS with Web SSH, the behavior of 'space' and '?' in keyboard are different with normal PuTTY or console.

818585

Web SSH cursor issues.

891437

Web SSH cursor is not at the correct position.

865237

The Launch Secret button and the pwd-chg-sch-start-date field are not acting correctly for the secrets created from CLI with automatic password changing set up.

875742

Information error for Web SSH/RDP/VNC.

883168, 876986,

877093

Secret list improvements.

860209

Wad trace GUI API support.

863356

Send test backup function to apache.

872633

Upgrade libssh2 to project trunk build.

876120, 869866

Web proxy keywords table.

885478

Revise layout in secret field so it is easier to edit.

873888

User with view permission to a secret with the 'View Encrypted information' role should be able to view secret password and key.

813008

New Secret > Allow for template switching without field conversion slide.

876629

SSH filter issues.

845705

Allow glass breaking user to launch any secret.

859888, 876121

Restrict the user from upgrading the account profile to a permission higher than they have.

864930

Prevent cmdb from adding a concurrent request.

875356

Allow check-out after check-in.

878496

Support right click to disable/enable a user.

879947

WebSFTP and WebSMB cannot be controlled from Service Setting.

882360

Password policy should not be available when the password changer type is 'SSH with Public Key'.

867177

Hide the Expires column by default in Monitor > Active Sessions.

867443

Add test email function to FortiPAM.

885138

Prevent blocklist and allowlist from being set at the same time.

865931

Port FortiOS ECO 218884: Openssl 3.0.

868521

When creating or cloning a launcher, 'File Launcher' setting is not available on the GUI.

877002

Add FQDN information in email notifications.

790421

VNC dsplay variable support.

810687

Add blocklist/allowlist to GUI API.

865012

Prevent user from setting up a web-app launcher to non-default launcher.

877355

Dynamic FQDN sometimes does not work for Web RDP.

877460

Enable SMS option in the user wizard.

870808

AV Profile not loading value.

879074

Wad crash when no passphrase field in the template.

874851

CLI does not show the FortiClient EMS endpoint in the available options to configure. Also, the CLI is missing 'autocomplete' for the feature.

862156

Change permission for the RADIUS test connection.

Common Vulnerabilities and Exposures

Bug ID

CVE references

912019

FortiPAM 1.1.0 is no longer vulnerable to the following CVE-Reference(s):

  • CVE-2023-37934

919845

FortiPAM 1.1.0 is no longer vulnerable to the following CVE-Reference(s):

  • CVE-2023-36640

Visit https://fortiguard.com/psirt for more information.

Resolved issues

Resolved issues

The resolved issues listed below may not list every bug that has been corrected with this release. For inquiries about a particular bug, please visit FortiCloud.

Bug ID

Description

927122

Client cert memory leak fix from FortiProxy.

926668

Wad crash when trying to allocate a zero length object.

925922

MySQL typo.

925112

Port from FPX: EMS Cloud Fabric Connector not working.

925675

Display create secret button in personal folder.

924904

WinSCP video file deleted if user clicks reconnect when current connection closed.

924771, 877090

Password changer crash.

924185

`FortiProduct (SSH Key) ` passphrase field is password type.

924967

wad crash when server side is disconnected

921159

Format string bug in httpsd and cli - automation test.

923591

Secret cannot be edited.

877321

Secret upload improvement.

922825

FortiPAM crashes when launching an associated secret to a Cisco server.

918137

Improved user authentication log and replacement message page.

923250

Refactor launch prompt error.

923237

Remove none option in template permission.

922963, 923131, 923599

Hide AV scan if no file launcher.

924403

wad crash when SFTP/SMB authentication request is expired or manually modified.

923988

Add upgrade function for alertemail mail to.

924050

Change the default value of inherit-folder-ztna to disable to avoid configuration lost in upgrade.

919761

Null pointer check to access permission table.

920067, 917965 919085, 920170 918877, 921268, 922752

The user does not have permission to use email service and other GUI issues.

922344

Folder permission validation.

921938

Fix HA sync issue when user password policy is enabled.

921071

SSH auto password delivery fails with server Cisco_7200.

922584

Hide SSL_ERROR_SSL error messages from console.

920106

LDAP/RADIUS 2FA authentication failure.

921742

Format address array.

920257

Use the original client IP for trusted host checking.

920458

Bypass approval feature.

920610, 0920637, 0919554

folder list clone update count.

920506

WAD crash was observed.

920208

Launching web account (FortiGate+DNS+FQDN) logs out the current user

919596

In a folder with `Add Secret` and Secret `List` permission; clone a secret shows empty fields.

897253

Automatically identify the correct remote server to authenticate a remote user.

919179

Hide unnecessary service.

919670

User info daemon crash.

918890

In target-only, target-address field cannot be empty.

918865

Request enforced for all secrets

863569

Non-proxy PuTTy should be disabled when using an SSH key.

920035

Invalid 'Approved Access' in secret.

919135

WAD crash observed on CM build 0418.

919133

miglogd crash observed on CM build 0418.

896180

FortiPAM hardware license.

918116, 919678

Provide an extra customized http header for extension to indicate video has finished.

804808, 904559

Support totp in SSH authentication.

884593, 0896564, 0890817, 0908686, 0884633

Optimize the navbar menu structure.

915230

Add PAM disk conserve mode.

918418

When installing FortiPAM for the first time, incorrect prompt when enabling email notification.

918485

Allow % in secret url field.

918346

Edit totp html.

913663

Occasionally, server list is stuck unless refreshed.

910784

Enable WebSMB service by default when creating a secret with template ' Unix Account (Web CIFS)'.

917965

api-user cannot add a secret job.

897541, 904137

Include email notification setting in the user wizard.

881157

Add new radio for user defined role in the user wizard.

882407

Job execution time display format issue.

0899609

Add regex and logic options to automation-trigger.

917750

Web app launching failure.

887801, 896115

Secret request refactor for multiple requests in one email.

914149

Add secret name on the title of edit page.

877321

Update template in upload xlsm.

887801, 908824

Add settings related to combine multiple requests into one email; support custom port for baseurl.

913639

Add authentication failure prompt to Web SSH.

886577, 0887801

Add user guide information for secret request email and vnc display number.

914744

HA heartbeat port mimics admin access configuration of port1.

887801

Combine multiple secret request notifications in one email to the approver.

915069

Mask password on release build.

899189

Display sudo disclaimer to user with SSH AUTO password.

914654

Update secret wad cache when template gets updated.

912655

PAM launching failure when NAT is in between.

798866, 913635

Job list execution status.

913523

Image restore from CLI failed when GUI pages are opened.

911223

Provide download blocking replacement message page to users for file blocked by av/dlp.

865654, 0885138, 0810687

Support AD restriction.

911262

Hide DLP settings in secret when AVDB license expires.

840512

Notify user when user number exceed licensed seats.

904137

License expiration notification and restriction.

903079

Enable editing the launcher for default secret templates.

827628

Secret edits fail after cloning.

908671, 912019

FortiPAM HTTP video storage backend refactor.

908444

Allow creation of api-user with schedule.

904438

Check secret duplication before clone.

897591, 853452

Add CLI launchers.

854712

Client software integrity check CLI support.

902469

Support multiple requests

899189

SSH auto password does not support sudo with disclaimer.

860158

Support Logs of AV and DLP on GUI.

905335

Support AntiVirus and DLP license validation check in the scan procedure of file transfer launchers.

912775

Grey out non-editable DLP default sensors.

914061

Missing DLP uploading file logs for Content_Archive and Content_Summary when launching WebSFTP and WebSMB.

845099

Add target only secret template.

868233, 866748

Multiple file transfer launchers cannot be launched within a single browser at the same time.

906492

Remove disclaimer failed login information.

893740

Modify table size for a different platform.

913687

User unable see secret when they do not have access to the template.

864749

Allow owner to bypass secret approval process.

814300

Improvements on user delete.

822815

Provide a way to explicitly download a secret video from the log page.

847167

Prohibit deleting a root personal folder from the GUI.

874509

Add validators for checking ssh private and public key format.

896096

Hide address types not needed when creating a new address or an address group.

897188

Web Launcher restriction not working.

906942

AWS account creation requires more validation.

911230

Add file size unit for DLP large-file.

910813

Multiple launchings with customized templates.

910780

Unnecessary 'Launch' button.

910297

Adding field type check for sensitive information field when switching templates.

905935

wad crash is observed; wad_aio_module_close closes during stress.

897304

Inherited folder permission should show up in details.

849255

Template and database user filter.

909683

Change all the FortiGate names in VMware ovf files.

909693

If the first firewall policy is disabled, FortiPAM GUI becomes unavailable.

848805

Display remaining time for approved requests.

893730

SSH launching fails after password change for the SSH key using template with password and passphrase.

910367

Optimize secret approval flag in the GUI API.

829558

Add two buttons that could go to the secret /secret video log page with targeted Token ID.

867911

Check RAID disk status every 5 minutes.

909198

PuTTY SSH connecting failure with the FortiTester server.

907267

Add a new parameter for the WinSCP launcher: /newinstance.

894252

Add status column for the job listing page.

851587

After running the execute shutdown CLI command on FortiPAM 3000G, it does not powered off and its console still echoes the received characters even after being halted.

909718

Format tje string bug in Fclicense daemon.

910007

DLP profile is invisible to standard users.

908190

Grey out the default password changers from the GUI.

879947

WebSFTP and WebSMB cannot be controlled from Service Setting.

909860

Failed to create a customized launcher.

898516

Add the Hyper-V faceplate layout.

872884

Application type in the log for WebSFTP and WebSMB is missing.

865722, 863356

Add the certificate related attribute and test connection to server button.

893484

After the factory reset, the GUI is not available from the default IP address.

802577

Single concurrent session to logout from all wad workers.

902540

The SSH logs page is showing previously displayed secret logs.

907427

Upgrade liburing to latest release version 2.3.

872589

Current system time is not correct when manually setting the time.

907485

The FortiPAM HTTP module is unable to receive complete HTTP POST body from FortiClient's uploaded video.

789786

Fatal error: unable to find "node_mod_common.h" during parallel build.

900435

Unable to delete the last entry of IPv4 trusted hosts for the user.

907101

Correct the typo in New user Definition(1.1).

904443

Able to create identical folder in FortiPAM.

906449

GUI stuck while opening a file with auto-password enabled.

897542

Option to enable/disable the admin login disclaimer and modify the corresponding text.

878078

Extesion Only: If launching a secret with Web SSH or Web FTP; only one session is recorded.

877879

Update the secret name on the favorite menu after changing the secret name in the edit page.

865931

LibGD to 2.3.3.

906156

Failed to create a new user.

905640

Enhance to forbid empty cluster password.

905233

RDP connection failure on the hardware box when recording.

865931

tcpdump vulnerabilities - precaution upgrade to 4.99.1.

886975

Add ZTNA secret launch control on folder.

894302

Separate settings for RADIUS/FAZ when using DR.

879947

Add SFTP service control.

897541

Include email notification setting in the user wizard.

882636, 902400, 865931

Upgrade OpenSSL to 3.0.8.

848549

Add a hint message for `Cisco Enable Secret` when no user secret is associated.

848549

New everyone default user group.

896750

Extend the shell prompt.

878581

When the admin is under the glass breaking mode, request status is not correct after the admin approves the request.

903204

Return the correct port media for FortiPAM3000G/1000G.

874662

SSH procedure needs at least one 'expect' field to work.

901345

When disabling the proxy mode on an SSH key secret, all the default launchers should be disabled.

872781

New access control option for disabling the non-proxy mode.

790421

VNC display variable support.

879582

When the FortiPAM feature is disabled in the EMS, the GUI should display an error message.

862589

Invalid alarm for a secret launching from a non-certificate client.

865453

When failed to connect to FortiClient; no prompt on Chrome.

861389

When there is no ForitClient and the user tries to launch the native launcher; should report an error.

860158

Support logs for AV and DLP on the GUI.

863268

Support DLP configuration on the GUI.

886975

Add "device control by ZTNA Tag" for folders.

902676

WAD SSH proxy could not connect to the Cisco router with KEX "diffie-hellman-group-exchange-sha1" + cipher "aes192-cbc".

893026

Timestamp of log when it is in DST.

865931

Use the correct package signatures.

817957

Update log summary time frame to 7 days.

892493

Change the faceplate port type to fiber to fit the appearance.

867443

Send test emails.

899908

Show "warning" or "disclaimer" when the admin logins to the interface IP address.

901484

Edge case for secret editing.

897253

Remove auto add LDAP/RADIUS server into the default authentication scheme database.

896177

Add FortiPAM upgrade code (template srv-info).

865931

Upgrade the KRB5 version to 1.19.4.

868811

Remove the downgrade configuration migration function.

865931

Upgrade sqlite version to 3.39.2.

849255

Template permission control.

810799

RDP restricted admin mode cannot auto log in to Windows 10/11.

865931

Upgrade curl to 7.86.

865722, 863851

Add certificate validation to automatic backup.

901632

Accept FortiPAM 1.0.x HA member if HA group passwd is empty.

842754, 899220

ZTNA layout enhancement.

865931

Upgrade OpenLDAP version to 2.6.3.

893198

New SecureCRT launcher.

858229, 832286

Only display the entry of public folder list and personal folder; routing enhancement.

865313, 882312

Delete 'SSH Auto-Password' tooltips and delete the job page web API text.

882077

Change FortiGate to FortiPAM on VMware ovf files.

884542

Adding the network diagnose tools support.

893123

FortiPAM 1000G/ 3000G: No disk information, disk health, disk attributes, and disk errors commands on FortiPAM OS.

863354

Add port option to the backup server.

880074

When creating a new role, present the standard user's setting.

883168

Enhancement for Secret List view.

891436

Secret search under associated secret does not work.

890272

Enhancement on managing auto password changing.

893913

View button disappears for credential history.

845705

Allow launching secrets when admin is in the glass breaking mode.

879947

Add SFTP service setting.

863198

Update secret verification status after verification.

845087

Edit View tabs: Place actions above tabs.

891441

Add secret policy clone functionality.

805806

Syntax limitation: The format of [Variable] or Variable# is not allowed.

865012

Remove web launchers from the launcher type drowdown.

896180

Hardcode initial seats to 1000G/3000G.

889961

Support GPT partitions and EXT4 file systems for KVM and VMware platforms.

893356

Update API version to match the firmware version.

849255

Support template clone and add permission flag for template response.

892493

Rearrange port to fit machine appearance.

884631

Rename 'Launch Device Control' to 'ZTNA Control'.

883808, 868242

FortiPAM 1000G/3000G hardware RAID CLI execute raid create-and-format and diagnose system raid status commands.

896615

Fix FortiToken cloud issue on manually inputting a wrong token.

876725, 840559

Escape special characters in navigation URL.

883477

Use reply-to email as sender address.

871639

Support FortiToken mobile push configured on the FortiAuthenticator side.

893897

Change password visibility process.

893696

SSH auto password does not work when both key and password exist for a secret without an associated secret.

883565

Command log shows the wrong Login user for Web SSH.

877090

Moving multiple secrets and give the option of displaying failed secrets.

849255

Template permission support.

877321

Improve upload procedure to support other templates.

876120

Add commands for web launcher proxy (web-authentication).

891441

Add clone flag to secret policy.

841234

Limit the number of characters in name and email fields to 64.

874658

Prevent job new-line from reverting to the default password changer.

889961

Support GPT partitions and EXT4 file systems for KVM and VMware platforms.

894051

Adjust the secret list API handler so the GUI does not fail.

865731

Set maximum body size for the internal API.

891001

Authentication configuration mandatory field need to be highlighted.

877131

Secret creation/cloning attribute not maintained.

817710

GUI should show the full log message and would be better if the log messages only show changed configurations.

890376

Web SSH crashes when using associated secret authentication.

889900

SSH secret with PuTTY launcher in the proxy mode fails when authenticated with an associate secret.

872781

New access control option for disabling the non-proxy mode.

888479

Fix the secret UUID in the log.

891206

Remove the domain field in the login page when SAML is not configured.

884995

Rename 'Edit Secret' and 'Undo Changes'.

890568

Delete the 16-bit option recording color depth.

827547

When launching on the Cisco OS with Web SSH, the behavior of 'space' and '?' in keyboard are different with normal PuTTY or console.

818585

Web SSH cursor issues.

891437

Web SSH cursor is not at the correct position.

865237

The Launch Secret button and the pwd-chg-sch-start-date field are not acting correctly for the secrets created from CLI with automatic password changing set up.

875742

Information error for Web SSH/RDP/VNC.

883168, 876986,

877093

Secret list improvements.

860209

Wad trace GUI API support.

863356

Send test backup function to apache.

872633

Upgrade libssh2 to project trunk build.

876120, 869866

Web proxy keywords table.

885478

Revise layout in secret field so it is easier to edit.

873888

User with view permission to a secret with the 'View Encrypted information' role should be able to view secret password and key.

813008

New Secret > Allow for template switching without field conversion slide.

876629

SSH filter issues.

845705

Allow glass breaking user to launch any secret.

859888, 876121

Restrict the user from upgrading the account profile to a permission higher than they have.

864930

Prevent cmdb from adding a concurrent request.

875356

Allow check-out after check-in.

878496

Support right click to disable/enable a user.

879947

WebSFTP and WebSMB cannot be controlled from Service Setting.

882360

Password policy should not be available when the password changer type is 'SSH with Public Key'.

867177

Hide the Expires column by default in Monitor > Active Sessions.

867443

Add test email function to FortiPAM.

885138

Prevent blocklist and allowlist from being set at the same time.

865931

Port FortiOS ECO 218884: Openssl 3.0.

868521

When creating or cloning a launcher, 'File Launcher' setting is not available on the GUI.

877002

Add FQDN information in email notifications.

790421

VNC dsplay variable support.

810687

Add blocklist/allowlist to GUI API.

865012

Prevent user from setting up a web-app launcher to non-default launcher.

877355

Dynamic FQDN sometimes does not work for Web RDP.

877460

Enable SMS option in the user wizard.

870808

AV Profile not loading value.

879074

Wad crash when no passphrase field in the template.

874851

CLI does not show the FortiClient EMS endpoint in the available options to configure. Also, the CLI is missing 'autocomplete' for the feature.

862156

Change permission for the RADIUS test connection.

Common Vulnerabilities and Exposures

Bug ID

CVE references

912019

FortiPAM 1.1.0 is no longer vulnerable to the following CVE-Reference(s):

  • CVE-2023-37934

919845

FortiPAM 1.1.0 is no longer vulnerable to the following CVE-Reference(s):

  • CVE-2023-36640

Visit https://fortiguard.com/psirt for more information.