PT-2020-3628 · Davical+2 · Davical Andrew'S Web Libraries+2
Andrew Bartlett
·
Published
2020-04-15
·
Updated
2020-09-28
·
CVE-2020-11728
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DAViCal Andrew's Web Libraries (AWL) versions through 0.60
Description
The issue concerns a problem with session management in DAViCal Andrew's Web Libraries (AWL), where the session key is not sufficiently hard to guess. This allows an attacker to potentially impersonate a session if they can guess the microsecond time and the incrementing session id. The vulnerability may allow a remote attacker to access confidential data.
Recommendations
For versions through 0.60, consider implementing additional security measures to protect session management, such as using more secure session keys or implementing rate limiting to prevent brute-force guessing of session IDs.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Davical Andrew'S Web Libraries
Linuxmint
Ubuntu