← Back
CWE-384

424 CVEs • Abstraction: Compound

Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

JSON object

Loading...

CVEs (424)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Enhancesoft
1Osticket
Jun 17, 2026
Apr 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.
1Nextauth.js
1Next Auth
Jun 17, 2026
Mar 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A...Show more
NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A bad actor who can read traffic on the victim's network or who is able to social engineer the victim to click a manipulated login link could intercept and tamper with the authorization URL to **log in as the victim**, bypassing the CSRF protection. This is due to a partial failure during a compromised OAuth session where a session code is erroneously generated. This issue has been addressed in version 4.20.1. Users are advised to upgrade. Users unable to upgrade may using Advanced Initialization, manually check the callback request for state, pkce, and nonce against the provider configuration to prevent this issue. See the linked GHSA for details.Show less
1Moodle
1Moodle
Jun 17, 2026
Mar 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
1Fortinet
1Fortiweb
Jun 17, 2026
Feb 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through...Show more
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to infer the session identifier of other users and possibly usurp their session.Show less
1Sensiolabs
1Symfony
Jun 17, 2026
Feb 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the rest of session attr...Show more
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the rest of session attributes. Because this does not clear CSRF tokens upon login, this might enables same-site attackers to bypass the CSRF protection mechanism by performing an attack similar to a session-fixation. This issue has been fixed in the 4.4 branch.Show less
1Jenkins
1Keycloak Authentication
Jun 17, 2026
Jan 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.
1Jenkins
1Bitbucket Oauth
Jun 17, 2026
Jan 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
1Jenkins
1Openid Connect Authentication
Jun 17, 2026
Jan 26, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.
1Cuppacms
1Cuppacms
Jun 17, 2026
Jan 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrary user sessions.
1Fit2cloud
1Kubepi
Jun 17, 2026
Jan 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
KubePi is a modern Kubernetes panel. A session fixation attack allows an attacker to hijack a legitimate user session, versions 1.6.3 and below are susceptible. A patch will be released in version 1.6.4.
1Kluks
1Xingwall
Nov 21, 2024
Jan 6, 2023
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in kassi xingwall. This issue affects some unknown processing of the file app/controllers/oauth.js. The manipulation leads to session fixiation. The patch...Show more
A vulnerability, which was classified as critical, has been found in kassi xingwall. This issue affects some unknown processing of the file app/controllers/oauth.js. The manipulation leads to session fixiation. The patch is named e9f0d509e1408743048e29d9c099d36e0e1f6ae7. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217559.Show less
1Arubanetworks
1Aruba Edgeconnect Enterprise Orchestrator
Jun 17, 2026
Jan 5, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persist a session after a password reset or similar session clearing event. Successful...Show more
A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persist a session after a password reset or similar session clearing event. Successful exploitation of this vulnerability could allow an authenticated attacker to remain on the system with the permissions of their current session after the session should be invalidated in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned. Show less
1Hazelcast
2Hazelcast
Hazelcast Jet
Jun 17, 2026
Dec 29, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Haze...Show more
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.Show less
1Simmeth
1Lieferantenmanager
Jun 17, 2026
Dec 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. Th...Show more
An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. This is due to the credentials not being cleaned from the local storage after logout.Show less
1Mozilla
1Vpn
Jun 17, 2026
Dec 22, 2022
N/A· v4
7.6 HIGH· v3
N/A· v2
An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue...Show more
An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue is limited to cases where attacker and victim are sharing the same source IP and could allow the ability to view session states and disconnect VPN sessions. This vulnerability affects Mozilla VPN iOS 1.0.7 < (929), Mozilla VPN Windows < 1.2.2, and Mozilla VPN Android 1.1.0 < (1360).Show less
1Niceforyou
1Linear Emerge E3 Access Control Firmware
Jun 17, 2026
Dec 13, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation...Show more
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation. This vulnerability allows attackers to escalate privileges via unspecified vectors.Show less
1Tribalsystems
1Zenario
Jun 17, 2026
Nov 30, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to ses...Show more
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214589 was assigned to this vulnerability.Show less
1Maggioli
1Appalti & Contratti
Jun 17, 2026
Nov 21, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESSIONID cookie that is issued by the server at the first visit, the cookie value is not updated after...Show more
An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESSIONID cookie that is issued by the server at the first visit, the cookie value is not updated after a successful login.Show less
1Backclick
1Backclick
Jun 17, 2026
Nov 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identi...Show more
An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, aka Session Fixation.Show less
1Zoneminder
1Zoneminder
Jun 17, 2026
Nov 15, 2022
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.