An issue was discovered in AdaCore ada_web_services 20.0...
High severity
Unreviewed
Published
Sep 25, 2024
to the GitHub Advisory Database
•
Updated Sep 26, 2024
Description
Published by the National Vulnerability Database
Sep 25, 2024
Published to the GitHub Advisory Database
Sep 25, 2024
Last updated
Sep 26, 2024
An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.
References