CVE Vulnerabilities

CVE-2017-11149

Server-Side Request Forgery (SSRF)

Published: Aug 14, 2017 | Modified: Oct 09, 2019
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

Name Vendor Start Version End Version
Download_station Synology 3.2-2295 (including) 3.2-2295 (including)
Download_station Synology 3.3-2382 (including) 3.3-2382 (including)
Download_station Synology 3.3-2383 (including) 3.3-2383 (including)
Download_station Synology 3.3-2386 (including) 3.3-2386 (including)
Download_station Synology 3.4-2477 (including) 3.4-2477 (including)
Download_station Synology 3.4-2478 (including) 3.4-2478 (including)
Download_station Synology 3.4-2480 (including) 3.4-2480 (including)
Download_station Synology 3.4-2485 (including) 3.4-2485 (including)
Download_station Synology 3.4-2486 (including) 3.4-2486 (including)
Download_station Synology 3.4-2489 (including) 3.4-2489 (including)
Download_station Synology 3.4-2490 (including) 3.4-2490 (including)
Download_station Synology 3.4-2514 (including) 3.4-2514 (including)
Download_station Synology 3.4-2555 (including) 3.4-2555 (including)
Download_station Synology 3.4-2557 (including) 3.4-2557 (including)
Download_station Synology 3.4-2558 (including) 3.4-2558 (including)
Download_station Synology 3.5-2638 (including) 3.5-2638 (including)
Download_station Synology 3.5-2705 (including) 3.5-2705 (including)
Download_station Synology 3.5-2706 (including) 3.5-2706 (including)
Download_station Synology 3.5-2955 (including) 3.5-2955 (including)
Download_station Synology 3.5-2956 (including) 3.5-2956 (including)
Download_station Synology 3.5-2962 (including) 3.5-2962 (including)
Download_station Synology 3.5-2963 (including) 3.5-2963 (including)
Download_station Synology 3.5-2967 (including) 3.5-2967 (including)
Download_station Synology 3.5-2968 (including) 3.5-2968 (including)
Download_station Synology 3.5-2970 (including) 3.5-2970 (including)
Download_station Synology 3.5-2973 (including) 3.5-2973 (including)
Download_station Synology 3.5-2980 (including) 3.5-2980 (including)
Download_station Synology 3.5-2982 (including) 3.5-2982 (including)
Download_station Synology 3.8.0-3416 (including) 3.8.0-3416 (including)
Download_station Synology 3.8.1-3420 (including) 3.8.1-3420 (including)
Download_station Synology 3.8.2-3455 (including) 3.8.2-3455 (including)
Download_station Synology 3.8.3-3458 (including) 3.8.3-3458 (including)
Download_station Synology 3.8.4-3468 (including) 3.8.4-3468 (including)

References