An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. QTS 5.x, QuTS hero are not affected.
We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 4.5.4.2627 build 20231225 and later
| Software | From | Fixed in |
|---|---|---|
| qnap / qts | 4.5.4.2280-build_20230112 | 4.5.4.2280-build_20230112.x |
| qnap / qts | 4.5.4.2117-build_20220802 | 4.5.4.2117-build_20220802.x |
| qnap / qts | 4.5.4.2012-build_20220419 | 4.5.4.2012-build_20220419.x |
| qnap / qts | 4.5.4.1931-build_20220128 | 4.5.4.1931-build_20220128.x |
| qnap / qts | 4.5.4.1800-build_20210923 | 4.5.4.1800-build_20210923.x |
| qnap / qts | 4.5.4.1787-build_20210910 | 4.5.4.1787-build_20210910.x |
| qnap / qts | 4.5.4.1741-build_20210726 | 4.5.4.1741-build_20210726.x |
| qnap / qts | 4.5.4.1723-build_20210708 | 4.5.4.1723-build_20210708.x |
| qnap / qts | 4.5.4.1715-build_20210630 | 4.5.4.1715-build_20210630.x |
| qnap / qts | 4.5.4.1892-build_20211223 | 4.5.4.1892-build_20211223.x |
| qnap / qts | 4.5.4.2374-build_20230416 | 4.5.4.2374-build_20230416.x |
| qnap / qutscloud | c5.1.0.2498-build_20230822 | c5.1.0.2498-build_20230822.x |
| qnap / qts | 4.5.4.2627 | 4.5.4.2627.x |