FortiDLP
FortiDLP is a cloud-native endpoint DLP and Insider Risk Solution which is aimed at monitoring and Preventing Data Theft on the endpoint, across Windows, macOS and Linux.
Anthony_E
Community Manager
Community Manager
Article Id 357189
Description This article discusses JAZZ-208: Operator sessions are unable to expire.
Scope FortiDLP.
Solution

Release Date:

9th July, 2019.

 

Overview:

Operator sessions are kept alive by automatic polling of the Jazz Infrastructure API even when there is no user input.

 

Affected Products:

  • All Jazz Infrastructure up to and including version 5.0.2, and Jazz Cloud before 8th July 2019.

 

Unaffected Products:

  • Jazz Infrastructure from version 5.0.3 onwards, and the current Jazz Cloud.

 

Resolution:

This issue has been fixed in Jazz Infrastructure version 5.0.3.

 

On-premises installations running an affected version are advised to upgrade at the earliest convenience. Releases are available to download through the Jazz Networks support portal.

 

A fix was deployed to the Jazz Cloud on 8th July 2019. Jazz Cloud customers do not need to take any additional action.

 

Vulnerability Information:

Operator sessions on the following pages do not time out: #landing, #actions #cases/<id>, #admin/status, #forensics/user/<id>/passport/atlas, and #forensics/user/<id>/actions/atlas.

 

Acknowledgments:

Issue found internally by Jazz Networks.

 

Disclosure Timeline:

  • 20/06/2019 Issue found internally by Jazz Networks.
  • 20/06/2019 Root cause established.
  • 20/06/2019 Fix identified.
  • 08/07/2019 Patched Jazz Cloud released.
  • 09/07/2019 Patched Jazz Infrastructure released.
  • 09/07/2019 Vulnerability disclosed.
Contributors