Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Andrew\'s_web_libraries
(Davical)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 2 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-04-15 | CVE-2020-11729 | An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful. | Andrew\'s_web_libraries, Debian_linux | N/A | ||
2020-04-15 | CVE-2020-11728 | An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session. | Andrew\'s_web_libraries, Debian_linux | N/A |