PT-2026-95313 · Synology · Diskstation Manager
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Synology DiskStation Manager (DSM) versions prior to 7.2.1-69057-12
Synology DiskStation Manager (DSM) versions prior to 7.2.2-72806-9
Synology DiskStation Manager (DSM) versions prior to 7.3.2-86009-4
Synology DiskStation Manager (DSM) versions prior to 7.4-90075
Description
An improper neutralization of CRLF sequences, known as CRLF Injection, exists in the Sharing API. This issue allows remote authenticated users to write limited files if a victim clicks a sharing URL. CRLF Injection occurs when an application fails to properly filter Carriage Return (CR) and Line Feed (LF) characters, allowing an attacker to inject new lines into the HTTP response header.
Recommendations
Update to version 7.2.1-69057-12 or later.
Update to version 7.2.2-72806-9 or later.
Update to version 7.3.2-86009-4 or later.
Update to version 7.4-90075 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Diskstation Manager