The most recent version of AWL (0.61) describes fixes to better thwart session impersonation: https://gitlab.com/davical-project/awl/-/blob/r0.61/debian/changelog https://www.debian.org/security/2020/dsa-4660 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11728 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11729 The latest corresponding version of Davical (1.1.9.3) calls for AWL 0.61+ as well: https://gitlab.com/davical-project/davical/-/blob/r1.1.9.3/debian/control#L23
A commit references this bug: Author: rigoletto Date: Wed May 20 15:32:33 UTC 2020 New revision: 536003 URL: https://svnweb.freebsd.org/changeset/ports/536003 Log: devel/php-libawl: Update to 0.61 PR: 246534 Reported by: wlam <wlam+fbd@blanksquare.net> Changes: head/devel/php-libawl/Makefile head/devel/php-libawl/distinfo
A commit references this bug: Author: rigoletto Date: Wed May 20 15:35:10 UTC 2020 New revision: 536004 URL: https://svnweb.freebsd.org/changeset/ports/536004 Log: www/davical: Update to 1.1.9.3 PR: 246534 Reported by: wlam <wlam+fbd@blanksquare.net> Changes: head/www/davical/Makefile head/www/davical/distinfo head/www/davical/pkg-plist
Fixed. Thanks! :-D