CVE-2022-27620

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Aug 3, 2022
Updated: Jan 14, 2025
CWE ID 22

Summary

CVE-2022-27620 is a Path Traversal vulnerability affecting the webapi component in Synology SSO Server prior to version 2.2.3-0331. This issue allows remote, authenticated users to access arbitrary files on the system through unspecified vectors, posing a significant risk to data confidentiality. The vulnerability arises from an improper limitation of a pathname to a restricted directory, enabling attackers to bypass intended access controls and potentially gain unauthorized access to sensitive information. Successful exploitation may lead to data theft or unauthorized system modifications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share