CVE-2020-11728: Davical Andrew's Web Libraries
High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.
Affected products
- Davical Andrew's Web Libraries: up to and including 0.60
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
Published 2020-04-15. Last modified 2026-06-17.