CVE-2019-11829: OS Command Injection
Published Jun 30, 2019
·Updated
OS command injection vulnerability in driverssynoimportuser.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header.
Affected Software
1 affected component
Synology Calendar<2.3.1-0617
Event History
Jun 30, 2019
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-11829.
2
What is the severity of CVE-2019-11829?
The severity of CVE-2019-11829 is critical with a CVSS score of 9.8.
3
Which software is affected by CVE-2019-11829?
The Synology Calendar version up to 2.3.1-0617 is affected by CVE-2019-11829.
4
How does CVE-2019-11829 work?
CVE-2019-11829 is an OS command injection vulnerability that allows remote attackers to execute arbitrary commands via a crafted 'X-Real-IP' header.
5
Is there a fix available for CVE-2019-11829?
Yes, a fix is available. Users should update to Synology Calendar version 2.3.1-0617 or higher.