Synology-SA-18:50 Drive
Publish Time: 2018-08-27 16:56:19 UTC+8
Last Updated: 2019-04-01 11:26:44 UTC+8
- Severity
- Moderate
- Status
- Resolved
Abstract
A vulnerability allows remote attackers to obtain sensitive information via a susceptible version of Drive.
Affected Products
Product | Severity | Fixed Release Availability |
---|---|---|
Drive | Moderate | Upgrade to 1.1.2-10562 or above. |
Mitigation
None
Detail
- CVE-2018-13297
- Severity: Moderate
- CVSS3 Base Score: 5.3
- CVSS3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive system information via the dsm_path parameter.
Acknowledgement
Chun Han Hsiao
Revision
Revision | Date | Description |
---|---|---|
1 | 2018-08-27 | Initial public release. |
2 | 2019-04-01 | Disclosed vulnerability details. |