← Back
CWE-384

424 CVEs • Abstraction: Compound

Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

JSON object

Loading...

CVEs (424)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Terra Master
1Terramaster Operating System
Nov 21, 2024
Nov 27, 2018
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript.
1Tryton
1Tryton
Nov 21, 2024
Nov 22, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection attempt fails, but it contains in the he...Show more
The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection attempt fails, but it contains in the header the current session of the user. This session could then be stolen by a man-in-the-middle.Show less
1Broadcom
1Fabric Operating System
Jun 17, 2026
Nov 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the web management interface of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow attackers to intercept or manipulate a user's session ID.
1Gitea
1Gitea
Nov 21, 2024
Nov 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.
1Gogs
1Gogs
Nov 21, 2024
Nov 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling...Show more
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.Show less
1Synology
1Photo Station
Nov 21, 2024
Oct 31, 2018
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Oct 30, 2018
N/A· v4
3.1 LOW· v3
3.6 LOW· v2
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
1Bigtreecms
1Bigtree Cms
Nov 21, 2024
Oct 19, 2018
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to the application. The Session Fixation cou...Show more
A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to the application. The Session Fixation could allow an attacker to hijack an admin session.Show less
1Yokogawa
4Fcj Firmware
Fcn 100 FirmwareFcn 500 Firmware+1 more
Nov 21, 2024
Oct 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote managemen...Show more
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.Show less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Jun 17, 2026
Sep 28, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's accountShow less
1Philips
1E Alert Firmware
Jun 17, 2026
Sep 26, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the opportunity to steal authenticated sessions w...Show more
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the opportunity to steal authenticated sessions without invalidating any existing session identifier.Show less
1Redhat
1Gluster Storage
Nov 21, 2024
Sep 11, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffin...Show more
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and authenticate as the target user.Show less
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Aug 6, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// lin...Show more
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 126861.Show less
1Redhat
1Keycloak
Nov 21, 2024
Aug 1, 2018
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to...Show more
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.Show less
1Navarino
1Infinity
Jun 17, 2026
Jul 24, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing at...Show more
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing attacks that can bypass the two factor authentication that is present in some installations.Show less
1Mozilla
1Network Security Services
Nov 21, 2024
Jul 19, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.
1Wondercms
1Wondercms
Nov 21, 2024
Jul 18, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the s...Show more
An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can access the user's account through the active session. The Session Fixation attack fixes a session on the victim's browser, so the attack starts before the user logs in.Show less
1Ieasytec
1Itrackeasy
Nov 21, 2024
Jul 13, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessi...Show more
Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be terminated when the user changes the associated password.Show less
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Jul 10, 2018
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.
1Jenkins
1Saml
Nov 21, 2024
Jun 26, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication sessio...Show more
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.Show less