Lucene search

K
cveGitHub_MCVE-2023-37919
HistoryJul 25, 2023 - 9:15 p.m.

CVE-2023-37919

2023-07-2521:15:10
CWE-613
GitHub_M
web.nvd.nist.gov
36
cal.com
scheduling software
open-source
vulnerability
2fa
active sessions
account security
nvd
cve-2023-37919

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

21.6%

Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain active even after enabling 2FA. When activating 2FA on a Cal.com account that is logged in on two or more devices, the account stays logged in on the other device(s) stays logged in without having to verify the account owner’s identity. As of time of publication, no known patches or workarounds exist.

Affected configurations

Nvd
Vulners
Node
calcal.comRange3.1.4
VendorProductVersionCPE
calcal.com*cpe:2.3:a:cal:cal.com:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "calcom",
    "product": "cal.com",
    "versions": [
      {
        "version": "<= 3.1.4",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

21.6%

Related for CVE-2023-37919