CWE-384
Session Fixation
Description
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61
CVEs mapped to this weakness (453)
page 11 of 23| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-5406 | Hig | 0.47 | 7.2 | 0.01 | Aug 9, 2019 | A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | ||
| CVE-2026-92984 | Hig | 0.46 | 8.1 | 0.00 | Sep 17, 2026 | HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and… | ||
| CVE-2024-56529 | Hig | 0.46 | 7.1 | 0.00 | Jan 28, 2025 | Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in, they are authenticated and the session identifier is valid. Then, a remote… | ||
| CVE-2023-24477 | Hig | 0.46 | 7.0 | 0.00 | Aug 9, 2023 | In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session. | ||
| CVE-2023-29019 | Hig | 0.46 | 8.1 | 0.01 | Apr 21, 2023 | @fastify/passport is a port of passport authentication library for the Fastify ecosystem. Applications using `@fastify/passport` in affected versions for user authentication, in combination with `@fastify/session` as the underlying session management mechanism, are vulnerable to… | ||
| CVE-2018-11385 | Hig | 0.46 | 8.1 | 0.02 | Jun 13, 2018 | An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a… | ||
| CVE-2016-0721 | Hig | 0.46 | 8.1 | 0.02 | Apr 21, 2017 | Session fixation vulnerability in pcsd in pcs before 0.9.157. | ||
| CVE-2016-6043 | Hig | 0.46 | 7.0 | 0.00 | Feb 1, 2017 | Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced. | ||
| CVE-2026-78428 | Hig | 0.45 | 8.0 | 0.00 | Sep 17, 2026 | For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently | ||
| CVE-2025-46815 | Hig | 0.45 | 8.0 | 0.00 | May 6, 2025 | The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for authentication, known as idp intents. Following a successful idp intent, the client receives an id and token on a… | ||
| CVE-2023-40273 | Hig | 0.45 | 8.0 | 0.02 | Aug 23, 2023 | The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user. Other than manually cleaning the session database (for… | ||
| CVE-2022-2997 | Hig | 0.45 | 8.0 | 0.01 | Aug 25, 2022 | Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10. | ||
| CVE-2025-26658 | Med | 0.44 | 6.8 | 0.00 | Mar 11, 2025 | The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper session management, the attackers can elevate themselves to higher privilege and… | ||
| CVE-2024-42170 | Med | 0.44 | 6.8 | 0.00 | Jan 11, 2025 | HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session. | ||
| CVE-2023-5309 | Med | 0.44 | 6.8 | 0.01 | Nov 7, 2023 | Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations. | ||
| CVE-2022-3916 | Med | 0.44 | 6.8 | 0.01 | Sep 20, 2023 | A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This… | ||
| CVE-2021-22237 | Med | 0.43 | 6.6 | 0.01 | Aug 25, 2021 | Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2 | ||
| CVE-2019-17563 | Hig | 0.43 | 7.5 | 0.11 | Dec 23, 2019 | When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the… | ||
| CVE-2018-0229 | Med | 0.43 | 6.5 | 0.03 | Apr 19, 2018 | A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platforms, Cisco Adaptive Security Appliance (ASA) Software, and Cisco Firepower Threat Defense (FTD)… | ||
| CVE-2026-13707 | Hig | 0.42 | 7.6 | 0.00 | Jul 1, 2026 | Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9. |
- risk 0.47cvss 7.2epss 0.01
A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
- risk 0.46cvss 8.1epss 0.00
HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and…
- risk 0.46cvss 7.1epss 0.00
Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in, they are authenticated and the session identifier is valid. Then, a remote…
- risk 0.46cvss 7.0epss 0.00
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.
- risk 0.46cvss 8.1epss 0.01
@fastify/passport is a port of passport authentication library for the Fastify ecosystem. Applications using `@fastify/passport` in affected versions for user authentication, in combination with `@fastify/session` as the underlying session management mechanism, are vulnerable to…
- risk 0.46cvss 8.1epss 0.02
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a…
- risk 0.46cvss 8.1epss 0.02
Session fixation vulnerability in pcsd in pcs before 0.9.157.
- risk 0.46cvss 7.0epss 0.00
Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.
- risk 0.45cvss 8.0epss 0.00
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
- risk 0.45cvss 8.0epss 0.00
The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for authentication, known as idp intents. Following a successful idp intent, the client receives an id and token on a…
- risk 0.45cvss 8.0epss 0.02
The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user. Other than manually cleaning the session database (for…
- risk 0.45cvss 8.0epss 0.01
Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
- risk 0.44cvss 6.8epss 0.00
The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper session management, the attackers can elevate themselves to higher privilege and…
- risk 0.44cvss 6.8epss 0.00
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.
- risk 0.44cvss 6.8epss 0.01
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
- risk 0.44cvss 6.8epss 0.01
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This…
- risk 0.43cvss 6.6epss 0.01
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2
- risk 0.43cvss 7.5epss 0.11
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the…
- risk 0.43cvss 6.5epss 0.03
A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platforms, Cisco Adaptive Security Appliance (ASA) Software, and Cisco Firepower Threat Defense (FTD)…
- risk 0.42cvss 7.6epss 0.00
Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.