CVE-2018-8922: Medium severity Synology Drive Server vulnerability
Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8922?
CVE-2018-8922 is classified as a medium severity vulnerability due to improper access control allowing unauthorized access to files.
How do I fix CVE-2018-8922?
To fix CVE-2018-8922, users should update Synology Drive or Synology Drive Server to version 1.0.2-10276 or later.
Who is affected by CVE-2018-8922?
CVE-2018-8922 affects remote authenticated users of Synology Drive and Synology Drive Server versions prior to 1.0.2-10276.
What kind of access does CVE-2018-8922 allow to attackers?
CVE-2018-8922 allows remote authenticated users to access non-shared files or folders that they should not have permissions for.
When was CVE-2018-8922 published?
CVE-2018-8922 was published in November 2018, highlighting a vulnerability in older versions of Synology Drive.