CWE-384
412 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Kiali Redhat2Kiali Openshift Service MeshJun 17, 2026 Apr 27, 2020 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using tha...Show more |
Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window,...Show more |
2Davical Debian2Andrew's Web Libraries Debian LinuxJun 17, 2026 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be...Show more |
2Davical Debian2Andrew's Web Libraries Debian LinuxJun 17, 2026 Apr 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing sess...Show more |
As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication. |
1Ibm 1Security Information Queue Jun 17, 2026 Apr 8, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176...Show more |
1Plathome 2Easyblocks Ipv6 Enterprise Firmware Easyblocks Ipv6 FirmwareJun 17, 2026 Apr 8, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 Session fixation vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier, and Enterprise Ver. 2.0.1 and earlier allows remote attackers to impersonate a registered user and log in the management console, that may result...Show more |
In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attacker team could potentially steal flags by...Show more |
An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0. |
IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may...Show more |
1Mitsubishielectric 1Iu1 1m20 D Firmware Jun 17, 2026 Mar 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions...Show more |
1Humaxdigital 1Hga12r 02 Firmware Jun 17, 2026 Mar 5, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking. |
1Western Digital 2Ibi My Cloud HomeJun 17, 2026 Feb 20, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation. |
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-28...Show more |
The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875. |
2Fedoraproject Mediawiki2Fedora MediawikiNov 21, 2024 Feb 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to...Show more |
1Ibm 1Infosphere Information Server Nov 21, 2024 Feb 5, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability |
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset. |
In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store...Show more |
2Infinispan Redhat2Infinispan Jboss Data GridJun 17, 2026 Jan 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling. |