CVE-2019-11820: Synology Calendar

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline.

Affected products

  • Synology Calendar: before 2.3.3-0620 (fixed in 2.3.3-0620)

Published 2019-05-09. Last modified 2026-06-17.