Impact
A server‑side request forgery flaw exists in the webhook handling of Synology Chat Server versions older than 2.4.5‑22148. The application will forward requests to arbitrary URLs supplied by a remote authenticated user, resulting in the disclosure of non‑sensitive data that can be accessed from within the network, such as internal addresses or basic configuration information. This weakness is classified as CWE‑918.
Affected Systems
Synology Chat Server components running any build prior to 2.4.5‑22148 are susceptible. The vulnerability applies to all installations of the chat server that have the webhook feature enabled in those versions.
Risk and Exploitability
The CVSS score of 4.3 places the issue in the moderate range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread, automated exploitation has not been observed. Attackers need to be authenticated to the chat service to trigger the flaw and would not gain code execution or privilege escalation, but could use the SSRF capability to probe internal resources and obtain non‑sensitive information.
OpenCVE Enrichment