An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.
https://www.debian.org/security/2020/dsa-4660
https://lists.debian.org/debian-lts-announce/2020/04/msg00011.html