CVE-2020-11729: Critical severity DAViCal Andrew\'s Web Libraries vulnerability
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11729?
CVE-2020-11729 is considered a moderate severity vulnerability due to its potential for brute-force attacks.
How do I fix CVE-2020-11729?
To mitigate CVE-2020-11729, upgrade to a patched version of the library, such as AWL 0.60-1+deb10u1, 0.62-1, or 0.64-1.
What software is affected by CVE-2020-11729?
CVE-2020-11729 affects versions of DAViCal's Andrew's Web Libraries (AWL) up to and including 0.60.
What are the risks if CVE-2020-11729 is not resolved?
If CVE-2020-11729 is not resolved, attackers may successfully perform brute-force attacks to hijack user sessions.
What environments are impacted by CVE-2020-11729?
CVE-2020-11729 impacts systems running Debian GNU/Linux, specifically versions 9.0 and 10.0 with affected AWL versions.