CVE-2022-27620: Path Traversal
Published Aug 3, 2022
·Updated
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server before 2.2.3-0331 allows remote authenticated users to read arbitrary files via unspecified vectors.
Affected Software
8 affected components
Synology SSO Server<2.2.3-0331
Synology Diskstation Manager=6.2
Synology Diskstation Manager=7.0
Synology Diskstation Manager=7.1
All of the following
Synology SSO Server<2.2.3-0331
Any of the following
Synology Diskstation Manager=6.2
Synology Diskstation Manager=7.0
Synology Diskstation Manager=7.1
Event History
Aug 3, 2022
CVE Published
via MITRE·02:55 AM
Data Sourced
via MITRE·02:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-27620.
2
What is the severity of CVE-2022-27620?
The severity of CVE-2022-27620 is medium (4.9).
3
What software is affected by CVE-2022-27620?
Synology SSO Server versions before 2.2.3-0331 are affected by CVE-2022-27620.
4
How does CVE-2022-27620 affect remote authenticated users?
CVE-2022-27620 allows remote authenticated users to read arbitrary files.
5
Is there a fix available for CVE-2022-27620?
Yes, it is recommended to update Synology SSO Server to version 2.2.3-0331 to fix CVE-2022-27620.