CVE-2017-11148: SSRF
Published Aug 11, 2017
·Updated
Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intranet resources via unspecified vectors.
Affected Software
1 affected component
Synology Chat<=1.0.2-0159
Event History
Aug 11, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-11148?
CVE-2017-11148 is classified as a medium severity vulnerability due to the potential unauthorized access to intranet resources.
2
How do I fix CVE-2017-11148?
To fix CVE-2017-11148, update Synology Chat to version 1.1.0-0806 or later.
3
Who is affected by CVE-2017-11148?
CVE-2017-11148 affects remote authenticated users of Synology Chat versions prior to 1.1.0-0806.
4
What type of vulnerability is CVE-2017-11148?
CVE-2017-11148 is a server-side request forgery (SSRF) vulnerability.
5
Can CVE-2017-11148 lead to data breaches?
Yes, CVE-2017-11148 could potentially lead to unauthorized access to sensitive intranet resources.