An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-04-15T15:37:12
Updated: 2024-08-04T11:41:59.965Z
Reserved: 2020-04-12T00:00:00
Link: CVE-2020-11728
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-15T16:15:16.643
Modified: 2024-11-21T04:58:29.770
Link: CVE-2020-11728
Redhat
No data.