CVE-2020-11729: Davical Andrew's Web Libraries

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.

Affected products

  • Davical Andrew's Web Libraries: up to and including 0.60
  • Debian Debian Linux: version 9.0 only; version 10.0 only

Published 2020-04-15. Last modified 2026-06-17.