First published: Thu Aug 10 2017(Updated: )
Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intranet resources via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Chat | <=1.0.2-0159 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11148 is classified as a medium severity vulnerability due to the potential unauthorized access to intranet resources.
To fix CVE-2017-11148, update Synology Chat to version 1.1.0-0806 or later.
CVE-2017-11148 affects remote authenticated users of Synology Chat versions prior to 1.1.0-0806.
CVE-2017-11148 is a server-side request forgery (SSRF) vulnerability.
Yes, CVE-2017-11148 could potentially lead to unauthorized access to sensitive intranet resources.