Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqhq-jmhf-8j84

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.

EPSS

Процентиль: 63%
0.0045
Низкий

7.5 High

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.

CVSS3: 7.5
nvd
почти 6 лет назад

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.

CVSS3: 7.5
debian
почти 6 лет назад

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) throug ...

CVSS3: 7.5
fstec
почти 6 лет назад

Уязвимость набора библиотек awl, связанная с ошибками управления сеансом, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 63%
0.0045
Низкий

7.5 High

CVSS3

Дефекты

CWE-384