Debian Awl vulnerabilities
2 known vulnerabilities affecting debian/awl.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2020-11729P3CRITICALCVSS 9.8fixed in awl 0.61-1 (bookworm)2020
CVE-2020-11729 [CRITICAL] CVE-2020-11729: awl - An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Lo...
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.
Scope: local
bookworm: resolved (fixed in 0.61-1)
bullseye: resolved (fixed in 0.61-1)
forky: resolved (fixed in 0.61-1)
sid: resolved
debian
CVE-2020-11728P3HIGHCVSS 7.5fixed in awl 0.61-1 (bookworm)2020
CVE-2020-11728 [HIGH] CVE-2020-11728: awl - An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Se...
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.
Scope: local
bookworm: resolved (fixed in 0.61-1)
bullseye: resolved (fixed in 0.61-1)
forky: resolved (fixed in 0.61
debian