PT-2020-3628 · Davical+2 · Davical Andrew'S Web Libraries+2

Andrew Bartlett

·

Published

2020-04-15

·

Updated

2020-09-28

·

CVE-2020-11728

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions DAViCal Andrew's Web Libraries (AWL) versions through 0.60
Description The issue concerns a problem with session management in DAViCal Andrew's Web Libraries (AWL), where the session key is not sufficiently hard to guess. This allows an attacker to potentially impersonate a session if they can guess the microsecond time and the incrementing session id. The vulnerability may allow a remote attacker to access confidential data.
Recommendations For versions through 0.60, consider implementing additional security measures to protect session management, such as using more secure session keys or implementing rate limiting to prevent brute-force guessing of session IDs. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03975
CVE-2020-11728
DLA-2178-1
DSA-4660-1
USN-4539-1

Affected Products

Davical Andrew'S Web Libraries
Linuxmint
Ubuntu