CWE-384— Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.— MITRE CWE catalog
420 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-384page 6 of 9
- CVE-2023-1265MEDIUMCVSS 5.4EG 5.42023-05-03
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacke…
- CVE-2023-2105HIGHCVSS 8.8EG 8.82023-04-15
Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
- CVE-2023-21238MEDIUMCVSS 5.5EG 5.52023-07-13
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…
- CVE-2023-21239MEDIUMCVSS 5.5EG 5.52023-07-13
In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction…
- CVE-2023-22479HIGHCVSS 7.5EG 7.52023-01-10
KubePi is a modern Kubernetes panel. A session fixation attack allows an attacker to hijack a legitimate user session, versions 1.6.3 and below are susceptible. A patch will be released in version 1.6.4.
- CVE-2023-24424HIGHCVSS 8.8EG 8.82023-01-26
Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.
- CVE-2023-24427CRITICALCVSS 9.8EG 9.82023-01-26
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
- CVE-2023-24444CRITICALCVSS 9.8EG 9.82023-01-26
Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.
- CVE-2023-24456CRITICALCVSS 9.8EG 9.82023-01-26
Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.
- CVE-2023-24477HIGHCVSS 7.0EG 7.02023-08-09
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces t…
- CVE-2023-26260MEDIUMCVSS 5.4EG 5.42023-04-11
OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.
- CVE-2023-27490HIGHCVSS 8.1EG 8.12023-03-09
NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A bad actor who can r…
- CVE-2023-28316CRITICALCVSS 9.8EG 9.82023-05-09
A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an attacker to maintain access to a co…
- CVE-2023-28809HIGHCVSS 7.5EG 7.52023-06-15
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the s…
- CVE-2023-29019HIGHCVSS 8.1EG 8.12023-04-21
@fastify/passport is a port of passport authentication library for the Fastify ecosystem. Applications using `@fastify/passport` in affected versions for user authentication, in combination with `@fastify/session` as the underlying session…
- CVE-2023-29020MEDIUMCVSS 6.5EG 6.52023-04-21
@fastify/passport is a port of passport authentication library for the Fastify ecosystem. The CSRF (Cross-Site Request Forger) protection enforced by the `@fastify/csrf-protection` library, when combined with `@fastify/passport` in affecte…
- CVE-2023-30056HIGHCVSS 7.5EG 7.52023-05-09
A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection of the JSESSIONID cookie.
- CVE-2023-30307MEDIUMCVSS 5.3EG 5.32024-05-28
An issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-R476G routers allows attackers to hijack TCP sessions which could lead to a denial of service.
- CVE-2023-31498CRITICALCVSS 9.8EG 9.82023-05-11
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.
- CVE-2023-3192MEDIUMCVSS 5.4EG 5.42023-06-11
Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.
- CVE-2023-32997HIGHCVSS 8.8EG 8.82023-05-16
Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login.
- CVE-2023-33005HIGHCVSS 5.4EG 8.82023-05-16
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
- CVE-2023-3394MEDIUMCVSS 5.4EG 6.82023-06-23
Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1.
- CVE-2023-34156MEDIUMCVSS 5.3EG 5.32023-06-19
Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause services to be denied.
- CVE-2023-34656HIGHCVSS 8.8EG 8.82023-06-29
An issue was discovered with the JSESSION IDs in Xiamen Si Xin Communication Technology Video management system 3.1 thru 4.1 allows attackers to gain escalated privileges.
- CVE-2023-3711MEDIUMCVSS 6.4EG 6.42023-09-12
Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available …
- CVE-2023-37946HIGHCVSS 8.8EG 8.82023-07-12
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.
- CVE-2023-38002MEDIUMCVSS 5.0EG 5.02024-04-30
IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or manipulate an active session to gain access to the system. IBM X-Force ID: 260208.
- CVE-2023-38018MEDIUMCVSS 6.3EG 6.32024-08-12
IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574.
- CVE-2023-40273HIGHCVSS 8.0EG 8.02023-08-23
The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user. Other than manually…
- CVE-2023-41012CRITICALCVSS 9.8EG 9.82023-09-05
An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.
- CVE-2023-42322CRITICALCVSS 9.8EG 9.82023-09-20
Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information.
- CVE-2023-44400HIGHCVSS 7.8EG 7.82023-10-09
Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verification of Session Tokens after password changes and/or elap…
- CVE-2023-45687HIGHCVSS 8.8EG 8.82023-10-16
A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server's authentication if they can trick an administrator into authorizating a session id…
- CVE-2023-45718LOWCVSS 3.9EG 3.92024-02-09
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed ou…
- CVE-2023-4649MEDIUMCVSS 5.4EG 5.42023-08-31
Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.
- CVE-2023-46733MEDIUMCVSS 6.5EG 6.52023-11-10
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after ev…
- CVE-2023-47798MEDIUMCVSS 5.4EG 5.42024-02-08
Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated user…
- CVE-2023-48929CRITICALCVSS 9.8EG 9.82023-12-08
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.
- CVE-2023-49804HIGHCVSS 7.8EG 7.82023-12-11
Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, when a user changes their login password in Uptime Kuma, a previously logged-in user retains access without being logged out. This behavior persists consis…
- CVE-2023-50176HIGHCVSS 7.5EG 7.52024-11-12
A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.
- CVE-2023-50270MEDIUMCVSS 6.5EG 6.52024-02-20
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.
- CVE-2023-50920MEDIUMCVSS 5.5EG 5.52024-01-12
An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session identifiers between different sessions and bypass authentication or access control…
- CVE-2023-50941MEDIUMCVSS 6.3EG 6.32024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation. IBM X-Force ID: 275131.
- CVE-2023-52268CRITICALCVSS 9.1EG 9.12024-11-12
The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freesco…
- CVE-2023-52353HIGHCVSS 7.5EG 7.52024-01-21
An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.
- CVE-2023-5309CRITICALCVSS 9.8EG 9.82023-11-07
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
- CVE-2023-53741HIGHCVSS 8.1EG 8.12025-12-10
Screen SFT DAB 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP address-bound session identifiers. Attackers can exploit the vulnerable API by intercepting and reu…
- CVE-2023-53775MEDIUMCVSS 6.5EG 6.52025-12-10
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requ…
- CVE-2023-53776HIGHCVSS 8.8EG 8.82025-12-10
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to exploit weak session management by reusing IP-bound session identifiers. Attackers can issue unauthorized requests to the device management API b…
Map vulnerabilities like CWE-384 to your infrastructure
EchelonGraph correlates every CVE — across CWE-384 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →