First published: Fri Nov 22 2024(Updated: )
A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
<3.9.7 |
We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38645 is classified as a server-side request forgery (SSRF) vulnerability which poses a significant risk to affected systems.
To mitigate CVE-2024-38645, upgrade to Notes Station 3 version 3.9.7 or later, where the vulnerability has been addressed.
CVE-2024-38645 specifically affects Notes Station 3 versions prior to 3.9.7.
If exploited, CVE-2024-38645 could allow remote authenticated attackers to read sensitive application data.
There is no public information indicating that CVE-2024-38645 is currently under active exploitation, but it is recommended to apply the fix promptly.