CVE-2018-13281: Infoleak
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the filepath parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-13281?
CVE-2018-13281 is an information exposure vulnerability in the SYNO.Core.ACL component of Synology DiskStation Manager (DSM) prior to version 6.2-23739-2.
How does CVE-2018-13281 impact Synology DiskStation Manager?
CVE-2018-13281 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.
What is the severity of CVE-2018-13281?
The severity of CVE-2018-13281 is medium with a CVSS score of 4.3.
Which versions of Synology DiskStation Manager are affected by CVE-2018-13281?
Synology DiskStation Manager versions prior to 6.2-23739-2 and 6.1.7-15284-2 are affected by CVE-2018-13281.
How can I fix CVE-2018-13281?
To fix CVE-2018-13281, upgrade your Synology DiskStation Manager to version 6.2-23739-2 or later.