An issue was discovered in DAViCal Andrews Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Andrew’s_web_libraries | Davical | * | 0.60 (including) |
Awl | Ubuntu | bionic | * |
Awl | Ubuntu | eoan | * |
Awl | Ubuntu | focal | * |
Awl | Ubuntu | trusty | * |
Awl | Ubuntu | upstream | * |
Awl | Ubuntu | xenial | * |
Such a scenario is commonly observed when: