First published: Thu Jul 28 2022(Updated: )
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4.0-0062 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology WebDAV Server | <2.4.0-0062 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22685 is an improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in the webapi component in Synology WebDAV Server.
CVE-2022-22685 allows remote authenticated users to delete arbitrary files in Synology WebDAV Server.
CVE-2022-22685 has a severity level of 8.1, which is considered high.
To fix CVE-2022-22685, upgrade to version 2.4.0-0062 or later of Synology WebDAV Server.
For more information about CVE-2022-22685, you can visit the Synology Security Advisory page at https://www.synology.com/security/advisory/Synology_SA_21_09.