Loading HuntDB...

GHSA-3vq2-5g7p-fgf2

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.

Related CVEs

Key Information

GHSA ID
GHSA-3vq2-5g7p-fgf2
Published
November 12, 2024 9:30 PM
Last Modified
November 14, 2024 9:32 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.