CVE-2021-33184: SSRF
Published Jun 1, 2021
·Updated
Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors.
Affected Software
1 affected component
Synology Download Station<3.8.15-3563
Event History
Jun 1, 2021
CVE Published
via MITRE·09:50 AM
Data Sourced
via MITRE·09:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-33184?
CVE-2021-33184 has a high severity rating due to its potential to allow remote authenticated users to read arbitrary files.
2
How do I fix CVE-2021-33184?
To mitigate CVE-2021-33184, upgrade Synology Download Station to version 3.8.15-3563 or later.
3
Who is affected by CVE-2021-33184?
Users of Synology Download Station versions prior to 3.8.15-3563 are affected by CVE-2021-33184.
4
What type of vulnerability is CVE-2021-33184?
CVE-2021-33184 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
5
What can attackers do with CVE-2021-33184?
Attackers exploiting CVE-2021-33184 may be able to read arbitrary files on the server.