First published: Thu Dec 28 2017(Updated: )
Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Chat | <2.0.0-1124 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15886 has a medium severity rating due to its potential for unauthorized local file access.
To mitigate CVE-2017-15886, update Synology Chat to version 2.0.0-1124 or later.
CVE-2017-15886 affects Synology Chat versions prior to 2.0.0-1124.
CVE-2017-15886 is classified as a server-side request forgery (SSRF) vulnerability.
Yes, CVE-2017-15886 can potentially lead to data breaches by allowing unauthorized access to sensitive local files.