Skip to main content
Toshi_Esumi
SuperUser
SuperUser
October 23, 2024
Solved

FMG 7.2.8

  • October 23, 2024
  • 3 replies
  • 3294 views

This version of FMG was released last week and now CVE-2024-47575 is released as well.
https://www.fortiguard.com/psirt/FG-IR-24-423
However, the release notes doesn't have anything in the resolved issue section. Does this actually have the vulnerability fix in it?
https://docs.fortinet.com/document/fortimanager/7.2.8/release-notes/972111/resolved-issues

Toshi

Best answer by Toshi_Esumi

Looks like somebody has just updated the release notes. I can see it there now.

Thanks,

Toshi

3 replies

Toshi_Esumi
SuperUser
Toshi_EsumiAuthorAnswer
SuperUser
October 23, 2024

Looks like somebody has just updated the release notes. I can see it there now.

Thanks,

Toshi

Toshi_Esumi
SuperUser
SuperUser
October 24, 2024

I swear I saw it there. But now it's gone. Only the change log is there with today's timestamp.

Toshi

Matt_B
Staff & Editor
Staff & Editor
October 29, 2024

Hi Toshi,

I can believe it. The Change Log has since been updated again and CVE-2024-47575 is referenced in Resolved Issues.

As you've noticed, not all Known or Resolved Issues appear immediately in Release Notes. Some never appear. For urgent releases to deal with a vulnerability, it may take some time for Resolved Issues to acknowledge the CVE.

In such cases, it is best to rely on the PSIRT information and any special security notification bulletins.

Matt

Is it a bug, is it a feature? It's... not in spec!