Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-11728

Опубликовано: 15 апр. 2020
Источник: debian
EPSS Низкий

Описание

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
awlfixed0.61-1package

Примечания

  • https://gitlab.com/davical-project/awl/-/issues/19

  • https://gitlab.com/davical-project/awl/-/commit/c2e808cc2420f8d870ac0a4aa9cc1f2c90562428

EPSS

Процентиль: 63%
0.0045
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.

CVSS3: 7.5
nvd
почти 6 лет назад

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.

CVSS3: 7.5
fstec
почти 6 лет назад

Уязвимость набора библиотек awl, связанная с ошибками управления сеансом, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 63%
0.0045
Низкий