First published: Thu Feb 24 2022(Updated: )
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Nas Proxy Server | <1.4.2 | |
QNAP QTS | >=4.5.1<=4.5.4 |
We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34359 is a cross-site scripting (XSS) vulnerability that affects QNAP devices running Proxy Server.
If exploited, CVE-2021-34359 allows remote attackers to inject malicious code into QNAP devices running Proxy Server.
Versions of Proxy Server up to and excluding 1.4.2 are affected by CVE-2021-34359.
Yes, this vulnerability has been fixed in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2.
CVE-2021-34359 has a severity rating of medium, with a CVSS score of 5.4.