Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.
2017-08-14T19:29:00.770
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | synology | download_station | 3.2-2295 | Yes |
| Application | synology | download_station | 3.3-2382 | Yes |
| Application | synology | download_station | 3.3-2383 | Yes |
| Application | synology | download_station | 3.3-2386 | Yes |
| Application | synology | download_station | 3.4-2477 | Yes |
| Application | synology | download_station | 3.4-2478 | Yes |
| Application | synology | download_station | 3.4-2480 | Yes |
| Application | synology | download_station | 3.4-2485 | Yes |
| Application | synology | download_station | 3.4-2486 | Yes |
| Application | synology | download_station | 3.4-2489 | Yes |
| Application | synology | download_station | 3.4-2490 | Yes |
| Application | synology | download_station | 3.4-2514 | Yes |
| Application | synology | download_station | 3.4-2555 | Yes |
| Application | synology | download_station | 3.4-2557 | Yes |
| Application | synology | download_station | 3.4-2558 | Yes |
| Application | synology | download_station | 3.5-2638 | Yes |
| Application | synology | download_station | 3.5-2705 | Yes |
| Application | synology | download_station | 3.5-2706 | Yes |
| Application | synology | download_station | 3.5-2955 | Yes |
| Application | synology | download_station | 3.5-2956 | Yes |
| Application | synology | download_station | 3.5-2962 | Yes |
| Application | synology | download_station | 3.5-2963 | Yes |
| Application | synology | download_station | 3.5-2967 | Yes |
| Application | synology | download_station | 3.5-2968 | Yes |
| Application | synology | download_station | 3.5-2970 | Yes |
| Application | synology | download_station | 3.5-2973 | Yes |
| Application | synology | download_station | 3.5-2980 | Yes |
| Application | synology | download_station | 3.5-2982 | Yes |
| Application | synology | download_station | 3.8.0-3416 | Yes |
| Application | synology | download_station | 3.8.1-3420 | Yes |
| Application | synology | download_station | 3.8.2-3455 | Yes |
| Application | synology | download_station | 3.8.3-3458 | Yes |
| Application | synology | download_station | 3.8.4-3468 | Yes |