An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-04-15T15:37:12

Updated: 2024-08-04T11:41:59.965Z

Reserved: 2020-04-12T00:00:00

Link: CVE-2020-11728

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-15T16:15:16.643

Modified: 2020-09-28T18:15:18.177

Link: CVE-2020-11728

cve-icon Redhat

No data.