Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability in Cal.com OSS allows authenticated users to create webhooks on any team, potentially exposing sensitive booking data such as attendee emails and custom responses. This could also grant access to video-call passwords, impacting data privacy and system integrity.
- Unauthorized webhook creation exposes booking data.
- Crucial to verify if your teams are affected.
- Confirming relevance and exposure is the priority.
Attack Path
How an attacker could exploit the issue
An attacker with existing access to Cal.com can exploit a flaw in how the system handles webhook creation. By leveraging an unvalidated team ID, they can set up a webhook for any team, including those they don't belong to. Once this webhook is established, triggering its delivery allows the attacker to access sensitive booking information and potentially video-call credentials.
- Authenticated user access required.
- Unvalidated team ID injection.
- Steal booking data and credentials.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow any authenticated user to create a webhook for any team, potentially leading to the theft of sensitive booking information. This includes organizer and attendee email addresses, custom responses, and, under certain conditions, video-call passwords, by triggering the delivery of these webhooks.
- Booking data and PII at risk.
- Authenticated users can inject team IDs.
- Booking details and meeting credentials may be stolen.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners and platform teams are likely responsible for addressing this authorization vulnerability in Cal.com OSS, as it impacts data integrity and potentially leads to data exfiltration. The immediate priority is to identify all instances of the affected technology, confirm their exposure and business criticality, and then locate the accountable owner to plan a risk-based remediation strategy.
- Confirm application ownership and deployment scope.
- Verify if any team webhooks are externally accessible.
- Plan remediation based on confirmed exposure and criticality.