An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.
{ "versions": [ { "introduced": "0" }, { "last_affected": "0.60" } ] }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-11729.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "9.0" } ] }, { "events": [ { "introduced": "0" }, { "last_affected": "10.0" } ] } ]