CVE-2020-11728: High severity DAViCal Andrew\'s Web Libraries vulnerability

Published Apr 13, 2020
·
Updated

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing sessionid) can impersonate a session.

Affected Software

8 affected componentsFixes available
debian/awl
0.60-1+deb10u10.62-10.64-1
ubuntu/awl<0.61-1
0.61-1
ubuntu/awl<0.60-1+
0.60-1+
debian/awl<=0.60-1, <=0.57-1
0.61-10.60-1+deb10u10.57-1+deb9u1
DAViCal Andrew\'s Web Libraries<=0.60
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0

Event History

Apr 15, 2020
CVE Published
12:00 AM
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
Description
Oct 21, 2023
Data Sourced
03:29 AM
Description

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2020-11728?

CVE-2020-11728 is classified as a medium severity vulnerability due to its impact on session management.

2

How do I fix CVE-2020-11728?

To resolve CVE-2020-11728, upgrade to versions 0.60-1+deb10u1, 0.62-1, or 0.64-1 for Debian and 0.61-1 for Ubuntu.

3

What types of applications are affected by CVE-2020-11728?

CVE-2020-11728 affects applications utilizing DAViCal Andrew's Web Libraries version 0.60 or lower.

4

Can CVE-2020-11728 lead to session hijacking?

Yes, CVE-2020-11728 can lead to session hijacking, allowing an attacker to impersonate a legitimate user.

5

Is CVE-2020-11728 related to specific operating systems?

Yes, CVE-2020-11728 affects Debian and Ubuntu operating systems in specific versions of the AWL package.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203