VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 15 of 22
  • CVE-2024-56733MedDec 30, 2024
    risk 0.37cvss 5.7epss 0.00

    Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has been reported in versions 1.50.3 and prior where an attacker can copy the session cookie before a user logs out, potentially allowing session hijacking. Although…

  • CVE-2023-49804MedDec 11, 2023
    risk 0.37cvss 6.7epss 0.00

    Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, when a user changes their login password in Uptime Kuma, a previously logged-in user retains access without being logged out. This behavior persists consistently, even after system restarts or…

  • CVE-2023-44400MedOct 9, 2023
    risk 0.37cvss 6.7epss 0.00

    Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verification of Session Tokens after password changes and/or elapsed inactivity periods. Version 1.23.3…

  • CVE-2024-42207MedFeb 5, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.

  • CVE-2024-28144MedDec 12, 2024
    risk 0.36cvss 5.5epss 0.00

    An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.

  • CVE-2024-50339MedDec 12, 2024
    risk 0.36cvss 5.3epss 0.20

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue.

  • CVE-2024-22318MedFeb 9, 2024
    risk 0.36cvss 5.1epss 0.01

    IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows…

  • CVE-2023-50920MedJan 12, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session identifiers between different sessions and bypass authentication or access control measures. Attackers can impersonate…

  • CVE-2023-21239MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21238MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-13282MedOct 31, 2018
    risk 0.36cvss 5.6epss 0.01

    Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

  • CVE-2018-0359MedJun 21, 2018
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session identifier, aka Session Fixation. The vulnerability exists because…

  • CVE-2026-69245MedAug 3, 2026
    risk 0.35cvss 6.5epss 0.00

    Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the…

  • CVE-2026-16089MedJul 17, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be…

  • CVE-2026-45773MedMay 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web…

  • CVE-2025-65415MedMay 11, 2026
    risk 0.35cvss 5.4epss 0.00

    docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application.

  • CVE-2025-55668MedAug 13, 2025
    risk 0.35cvss 6.5epss 0.01

    Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to…

  • CVE-2025-22216MedJan 31, 2025
    risk 0.35cvss 5.4epss 0.00

    A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.

  • CVE-2024-10318MedNov 6, 2024
    risk 0.35cvss 5.4epss 0.00

    A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in…

  • CVE-2023-50270MedFeb 20, 2024
    risk 0.35cvss 6.5epss 0.01

    Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.