davical-project/awl

davical-project/awl

Releases19
Frequency8 months 3 weeks
Last Release
Stars5
Andrew's Web Libraries

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.

9.8 CRITICAL7.5 HIGH

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.