Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
| synology / media_server | - | 1.4-2680 |
| synology / media_server | 2.0.0-11050 | 2.0.5-3152 |
| synology / media_server | 2.2.0-3324 | 2.2.0-3325 |