CVE-2020-11728: High severity DAViCal Andrew\'s Web Libraries vulnerability
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing sessionid) can impersonate a session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11728?
CVE-2020-11728 is classified as a medium severity vulnerability due to its impact on session management.
How do I fix CVE-2020-11728?
To resolve CVE-2020-11728, upgrade to versions 0.60-1+deb10u1, 0.62-1, or 0.64-1 for Debian and 0.61-1 for Ubuntu.
What types of applications are affected by CVE-2020-11728?
CVE-2020-11728 affects applications utilizing DAViCal Andrew's Web Libraries version 0.60 or lower.
Can CVE-2020-11728 lead to session hijacking?
Yes, CVE-2020-11728 can lead to session hijacking, allowing an attacker to impersonate a legitimate user.
Is CVE-2020-11728 related to specific operating systems?
Yes, CVE-2020-11728 affects Debian and Ubuntu operating systems in specific versions of the AWL package.