VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 16 of 22
  • CVE-2023-47798MedFeb 8, 2024
    risk 0.35cvss 5.4epss 0.00

    Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an…

  • CVE-2023-46733MedNov 10, 2023
    risk 0.35cvss 6.5epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in…

  • CVE-2023-33005MedMay 16, 2023
    risk 0.35cvss 5.4epss 0.00

    Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.

  • CVE-2023-1265MedMay 3, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain…

  • CVE-2023-29020MedApr 21, 2023
    risk 0.35cvss 6.5epss 0.00

    @fastify/passport is a port of passport authentication library for the Fastify ecosystem. The CSRF (Cross-Site Request Forger) protection enforced by the `@fastify/csrf-protection` library, when combined with `@fastify/passport` in affected versions, can be bypassed by network…

  • CVE-2023-26260MedApr 11, 2023
    risk 0.35cvss 5.4epss 0.00

    OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.

  • CVE-2022-33927MedAug 10, 2022
    risk 0.35cvss 5.4epss 0.00

    Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.

  • CVE-2021-41268MedNov 24, 2021
    risk 0.35cvss 6.5epss 0.01

    Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated when the user changes their password.…

  • CVE-2021-35948MedSep 7, 2021
    risk 0.35cvss 5.4epss 0.01

    Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.

  • CVE-2020-35591MedFeb 18, 2021
    risk 0.35cvss 5.4epss 0.01

    Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes…

  • CVE-2020-4954MedFeb 15, 2021
    risk 0.35cvss 5.4epss 0.01

    IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session using an attacker controlled IBM Spectrum Protect server, an…

  • CVE-2020-4555MedDec 21, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.

  • CVE-2019-4563MedOct 29, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to…

  • CVE-2019-19610MedMar 16, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0.

  • CVE-2020-5205MedJan 9, 2020
    risk 0.35cvss 6.5epss 0.01

    In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store, which is used in most Phoenix apps, doesn't have this…

  • CVE-2010-3671MedNov 5, 2019
    risk 0.35cvss 6.5epss 0.02

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.

  • CVE-2018-13337MedNov 27, 2018
    risk 0.35cvss 5.4epss 0.01

    Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript.

  • CVE-2018-17902MedOct 12, 2018
    risk 0.35cvss 5.3epss 0.01

    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.

  • CVE-2018-1000519MedJun 26, 2018
    risk 0.35cvss 6.5epss 0.01

    aio-libs aiohttp-session contains a Session Fixation vulnerability in load_session function for RedisStorage (see: https://github.com/aio-libs/aiohttp-session/blob/master/aiohttp_session/redis_storage.py#L42) that can result in Session Hijacking. This attack appear to be…

  • CVE-2017-2145MedJul 7, 2017
    risk 0.35cvss 5.4epss 0.01

    Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.