← Back
CWE-384

412 CVEs • Abstraction: Compound

Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

JSON object

Loading...

CVEs (412)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Kiali
Redhat
2Kiali
Openshift Service Mesh
Jun 17, 2026
Apr 27, 2020
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using tha...Show more
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.Show less
1Mozilla
1Firefox
Jun 17, 2026
Apr 24, 2020
N/A· v4
2.8 LOW· v3
1.9 LOW· v2
Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window,...Show more
Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75.Show less
2Davical
Debian
2Andrew's Web Libraries
Debian Linux
Jun 17, 2026
Apr 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be...Show more
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.Show less
2Davical
Debian
2Andrew's Web Libraries
Debian Linux
Jun 17, 2026
Apr 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing sess...Show more
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.Show less
1Argoproj
1Argo Cd
Jun 17, 2026
Apr 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.
1Ibm
1Security Information Queue
Jun 17, 2026
Apr 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176...Show more
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176334.Show less
1Plathome
2Easyblocks Ipv6 Enterprise Firmware
Easyblocks Ipv6 Firmware
Jun 17, 2026
Apr 8, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Session fixation vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier, and Enterprise Ver. 2.0.1 and earlier allows remote attackers to impersonate a registered user and log in the management console, that may result...Show more
Session fixation vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier, and Enterprise Ver. 2.0.1 and earlier allows remote attackers to impersonate a registered user and log in the management console, that may result in information alteration/disclosure via unspecified vectors.Show less
1Ctfd
1Rctf
Jun 17, 2026
Apr 1, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attacker team could potentially steal flags by...Show more
In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attacker team could potentially steal flags by, for example, exploiting a stored XSS payload in a CTF challenge so that victim teams who solve the challenge are unknowingly (and against their will) signed into the attacker team&#39;s account. Then, the attacker can gain points / value off the backs of the victims. This is patched in version 2.3.Show less
1Halvotec
1Raquest
Jun 17, 2026
Mar 16, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0.
1Ibm
1Cloud Automation Manager
Jun 17, 2026
Mar 16, 2020
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may...Show more
IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 168645.Show less
1Mitsubishielectric
1Iu1 1m20 D Firmware
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions...Show more
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions or execute malware via a specially crafted packet.Show less
1Humaxdigital
1Hga12r 02 Firmware
Jun 17, 2026
Mar 5, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.
1Western Digital
2Ibi
My Cloud Home
Jun 17, 2026
Feb 20, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.
1Keplerproject
1Cgilua
Nov 21, 2024
Feb 6, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-28...Show more
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.Show less
1Keplerproject
1Cgilua
Nov 21, 2024
Feb 6, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Nov 21, 2024
Feb 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to...Show more
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.Show less
1Ibm
1Infosphere Information Server
Nov 21, 2024
Feb 5, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
5.9 MEDIUM· v3
3.2 LOW· v2
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
1Powauth
1Pow
Jun 17, 2026
Jan 9, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store...Show more
In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store, which is used in most Phoenix apps, doesn't have this vulnerability.Show less
2Infinispan
Redhat
2Infinispan
Jboss Data Grid
Jun 17, 2026
Jan 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.