CWE-384
424 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (424)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Terra Master 1Terramaster Operating System Nov 21, 2024 Nov 27, 2018 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript. |
The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection attempt fails, but it contains in the he...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Nov 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the web management interface of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow attackers to intercept or manipulate a user's session ID. |
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron. |
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling...Show more |
Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter. |
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares. |
A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to the application. The Session Fixation cou...Show more |
1Yokogawa 4Fcj Firmware Fcn 100 FirmwareFcn 500 Firmware+1 moreNov 21, 2024 Oct 12, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote managemen...Show more |
1Lenovo 20Ez Media & Backup Center Firmware Ix2 FirmwareIx4 300d Firmware+17 moreJun 17, 2026 Sep 28, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a...Show more |
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the opportunity to steal authenticated sessions w...Show more |
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffin...Show more |
1Ibm 1Security Identity Governance And Intelligence Nov 21, 2024 Aug 6, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// lin...Show more |
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to...Show more |
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing at...Show more |
1Mozilla 1Network Security Services Nov 21, 2024 Jul 19, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA. |
An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the s...Show more |
Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessi...Show more |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreNov 21, 2024 Jul 10, 2018 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977. |
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication sessio...Show more |