First published: Thu Jul 28 2022(Updated: )
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to download arbitrary files via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Calendar | <2.3.4-0631 | |
Synology DiskStation Manager | =6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27617 is a vulnerability known as 'Path Traversal' in the webapi component of Synology Calendar before version 2.3.4-0631.
CVE-2022-27617 has a severity rating of 4.3, categorized as medium.
CVE-2022-27617 allows remote authenticated users to download arbitrary files in Synology Calendar before version 2.3.4-0631.
No, Synology DiskStation Manager version 6.2 is not vulnerable to CVE-2022-27617.
To fix CVE-2022-27617, update Synology Calendar to version 2.3.4-0631 or later.