Description | This article discusses JAZZ-220: Deleted operator sessions not cleared. |
Scope | FortiDLP. |
Solution |
Release Date: 29th October 2019.
Overview: Operators deleted by an admin could still access the Jazz Platform if they have an active session at the time of deletion. They could continue to access the Jazz Platform until their session expired.
Affected Products:
Unaffected Products:
Resolution: This issue has been fixed in Jazz Infrastructure version 6.1.0.
On-premises installations running an affected version are advised to upgrade at the earliest convenience. Releases are available to download through the Jazz Networks support portal.
A fix was deployed to the Jazz Cloud on 27th September, 2019. Jazz Cloud customers do not need to take any additional action.
Vulnerability Information: Sessions belonging to an operator were not invalidated if that operator was deleted from the Jazz Platform. The operator could continue to use the Jazz Platform if they had an active session at the time of deletion. This issue is mitigated by the operator logging out of the Jazz Platform, deleting cookies from their browser, or otherwise invalidating their session.
Acknowledgments: Ths issue was found internally by Jazz Networks.
Disclosure Timeline:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.