CWE-384
412 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
|
1Sielco 3Polyeco1000 Firmware Polyeco300 FirmwarePolyeco500 FirmwareJun 17, 2026 Oct 26, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attack, lack of SSL, and the session being visible in requests.
|
1Southrivertech 2Titan Mft Server Titan Sftp ServerJun 17, 2026 Oct 16, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server's authentication if they can trick an administrator into authori...Show more |
Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verification of Session Tokens after password...Show more |
Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. |
1Redhat 6Keycloak Openshift Container PlatformOpenshift Container Platform For Linuxone+3 moreJun 17, 2026 Sep 20, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session...Show more |
Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the...Show more |
1Chinamobile 1Intelligent Home Gateway Firmware Jun 17, 2026 Sep 5, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism. |
Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1. |
The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user....Show more |
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attack...Show more |
In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges neede...Show more |
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interactio...Show more |
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login. |
1Video Management System Project 1Video Management System Jun 17, 2026 Jun 29, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered with the JSESSION IDs in Xiamen Si Xin Communication Technology Video management system 3.1 thru 4.1 allows attackers to gain escalated privileges. |
Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1. |
Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause services to be denied. |
1Hikvision 26Ds K1t320efwx Firmware Ds K1t320efx FirmwareDs K1t320ewx Firmware+23 moreJun 17, 2026 Jun 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the...Show more |
Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0. |
Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login. |