CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
404 vulnerabilities with CWE-384
CVE-2023-29019
HIGH
@fastify/passport <1.1.0 - Session Fixation via Preserved sessionId
CVSS 8.1
CVE-2023-2105
HIGH
alextselegidis/easyappointments <1.5.0 - Info Disclosure
CVSS 8.8
CVE-2023-26260
MEDIUM
OXID eShop <6.4.4-6.5.2 - Info Disclosure
CVSS 5.4
CVE-2023-27490
HIGH
next-auth < 4.20.1 - Authentication Bypass via OAuth CSRF Protection Failure
CVSS 8.1
CVE-2023-24456
CRITICAL
Jenkins Keycloak Authentication Plugin <2.3.0 - Info Disclosure
CVSS 9.8
CVE-2023-24427
CRITICAL
Jenkins Bitbucket OAuth Plugin <0.12 - Auth Bypass
CVSS 9.8
CVE-2023-24424
HIGH
Jenkins OpenId Connect Authentication Plugin <2.4 - Auth Bypass
CVSS 8.8
CVE-2023-22479
HIGH
KubePi < 1.6.4 - Session Fixation
CVSS 7.5
CVE-2022-40916
CRITICAL
Tiny File Manager <2.4.7 - Session Fixation
CVSS 9.8
CVE-2022-46480
HIGH
Ultraloq UL3 2nd Gen Smart Lock <02.27.0012 - Info Disclosure
CVSS 8.1
CVE-2022-3916
MEDIUM
Keycloak < 20.0.2 - Insufficient Session Expiration via Offline Access Scope
CVSS 6.8
CVE-2022-31888
HIGH
osTicket <= 1.16.2 - Session Fixation in class.auth.php Login Function
CVSS 8.8
CVE-2022-24895
MEDIUM
Symfony 2.0.0-4.4.49 - Insufficient Session Expiration via CSRF Token Preservation
CVSS 6.3
CVE-2022-43529
MEDIUM
Aruba EdgeConnect Enterprise - Privilege Escalation
CVSS 4.6
CVE-2022-36437
CRITICAL
Hazelcast < 3.12.13 and Hazelcast Jet < 4.5.4 - Unauthenticated Session Fixation
CVSS 9.1
CVE-2022-44017
HIGH
Simmeth Lieferantenmanager <5.6 - Privilege Escalation
CVSS 7.5
CVE-2022-38628
MEDIUM
Nortek Linear eMerge E3-Series <0.32-09a - XSS
CVSS 6.1
CVE-2022-4231
MEDIUM
Tribal Systems Zenario CMS 9.3.57595 - Session Fixation
CVSS 4.2
CVE-2022-44788
MEDIUM
Appalti & Contratti 9.12.2 - Session Fixation
CVSS 6.5
CVE-2022-44007
HIGH
BACKCLICK Professional <5.9.63 - Privilege Escalation
CVSS 8.8
CVE-2022-30769
MEDIUM
ZoneMinder <1.36.12 - Info Disclosure
CVSS 4.6
CVE-2022-43687
MEDIUM
Concrete CMS <8.5.10, 9.0.0-9.1.2 - Info Disclosure
CVSS 5.4
CVE-2022-31689
CRITICAL
VMware Workspace ONE Assist <22.10 - Privilege Escalation
CVSS 9.8
CVE-2022-43398
HIGH
POWER METER SICAM Q100 < V2.50 - Info Disclosure
CVSS 7.5
CVE-2022-40293
CRITICAL
Phppointofsale PHP Point Of Sale - Session Fixation
CVSS 9.8
Details
Vulnerabilities
404