| Description | This article discusses JAZZ-186: Certificates for webhook remote endpoints that are not validated. |
| Scope | FortiDLP. |
| Solution |
Release Date: 28th May, 2019
Overview: Webhook HTTPS connections are created without validating the certificate of the target system.
Affected Products:
Unaffected Products:
Resolution: The issue is now fixed in Jazz Infrastructure 4.0.11.
It is strongly recommended that all on-premise installations running an affected version and that have any webhooks configured, upgrade to the latest release as soon as possible. Releases are available to download through the support portal. Jazz Cloud customers have already been upgraded to the latest version.
it is not possible to upgrade immediately, delete webhooks from the Jazz Infrastructure.
Vulnerability Information: JAZZ-186 leaves open the possibility for a Man In The Middle (MITM) to read or modify messages sent to configured webhooks. It would not be possible to alter data held within the Jazz Infrastructure.
Acknowledgments: Issue found internally by Jazz Networks.
Disclosure Timeline:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.