CVE-2022-27617: Path Traversal
Published Aug 3, 2022
·Updated
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to download arbitrary files via unspecified vectors.
Affected Software
4 affected components
All of the following
Synology Calendar<2.3.4-0631
Synology Diskstation Manager=6.2
Synology Calendar<2.3.4-0631
Synology Diskstation Manager=6.2
Event History
Aug 3, 2022
CVE Published
via MITRE·02:15 AM
Data Sourced
via MITRE·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-27617?
CVE-2022-27617 is a vulnerability known as 'Path Traversal' in the webapi component of Synology Calendar before version 2.3.4-0631.
2
What is the severity of CVE-2022-27617?
CVE-2022-27617 has a severity rating of 4.3, categorized as medium.
3
How does CVE-2022-27617 affect Synology Calendar?
CVE-2022-27617 allows remote authenticated users to download arbitrary files in Synology Calendar before version 2.3.4-0631.
4
Is Synology DiskStation Manager affected by CVE-2022-27617?
No, Synology DiskStation Manager version 6.2 is not vulnerable to CVE-2022-27617.
5
How can I fix CVE-2022-27617?
To fix CVE-2022-27617, update Synology Calendar to version 2.3.4-0631 or later.