CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

416 vulnerabilities with CWE-384
CVE-2023-30307 MEDIUM
TP-LINK TL-R473GP-AC, XDR6020, TL-R479GP-AC, TL-R4239G, TL-WAR1200L, TL-R476G - TCP Session Hijacking
CVSS 5.3
CVE-2023-38002 MEDIUM
IBM Storage Scale <5.1.9.2 - Privilege Escalation
CVSS 5.0
CVE-2023-50270 MEDIUM
Apache DolphinScheduler 1.3.8-3.2.0 - Insufficient Session Expiration
CVSS 6.5
CVE-2023-45718 LOW
HCL Sametime 11.5-12.0.1 - Insufficient Session Expiration in Web Client
CVSS 3.9
CVE-2023-47798 MEDIUM
Liferay Portal/DXP <7.3.0 - Privilege Escalation
CVSS 5.4
CVE-2023-50941 MEDIUM
IBM PowerSC <2.2 - Privilege Escalation
CVSS 6.3
CVE-2023-52353 HIGH
Mbed TLS < 3.5.2 - Session Fixation via TLS Version Mishandling
CVSS 7.5
CVE-2023-50920 MEDIUM
GL.iNet <4.5.0 - Privilege Escalation
CVSS 5.5
CVE-2023-6913 HIGH
Imou Life 6.7.0 - Session Hijacking via QR Code WebView Handling
CVSS 8.1
CVE-2023-49804 MEDIUM
Uptime Kuma <1.23.9 - Info Disclosure
CVSS 6.7
CVE-2023-48929 CRITICAL
Franklin Fueling Systems SSA <1.6.24.492 - Privilege Escalation
CVSS 9.8
CVE-2023-46733 MEDIUM
Symfony <5.4.31 & <6.3.8 - Info Disclosure
CVSS 6.5
CVE-2023-5309 MEDIUM
Puppet Enterprise <2021.7.6,2023.5 - Privilege Escalation
CVSS 6.8
CVE-2023-0897 HIGH
Sielco PolyEco1000 - Info Disclosure
CVSS 8.8
CVE-2023-45687 HIGH
South River Technologies - Privilege Escalation
CVSS 8.8
CVE-2023-44400 MEDIUM
Uptime Kuma <1.23.3 - Privilege Escalation
CVSS 6.7
CVE-2023-42322 CRITICAL
icmsdev iCMS 7.0.16 - Info Disclosure
CVSS 9.8
CVE-2023-3711 MEDIUM
Honeywell PM43 <P10.19.050004 - Session Fixation
CVSS 6.4
CVE-2023-41012 CRITICAL
China Mobile Intelligent Home Gateway v.HG6543C4 - RCE
CVSS 9.8
CVE-2023-4649 MEDIUM
instantsoft/icms2 <2.16.1 - Info Disclosure
CVSS 5.4
CVE-2023-40273 HIGH
Apache Airflow < 2.7.0 - Authenticated Session Fixation via Password Reset
CVSS 8.0
CVE-2023-24477 HIGH
Guardian/CMC <22.6.2 - Privilege Escalation
CVSS 7.0
CVE-2023-21239 MEDIUM
Android - Local Information Disclosure via Notification Image Data Leak
CVSS 5.5
CVE-2023-21238 MEDIUM
Android - Local Information Disclosure via RemoteViews visitUris
CVSS 5.5
CVE-2023-37946 HIGH
Jenkins OpenShift Login Plugin <1.1.0.227.v27e08dfb_1a_20 - Info Di...
CVSS 8.8
Details
Vulnerabilities 416