Weaknesses of type CWE-384

253 results

Fixação de Sessão

É quando um atacante consegue forçar um usuário a usar um ID de sessão conhecido por ele, geralmente reutilizando a mesma sessão antes e depois do login. Depois que a vítima se autentica com aquele ID fixo, o atacante usa o mesmo ID para acessar a conta sem precisar da senha.

Example

Um site gera um cookie de sessão antes do login. O atacante envia um link com esse ID de sessão para a vítima (ex: www.site.com?jsessionid=ATACANTE123), a vítima clica e faz login normalmente, mas o atacante já tem acesso à mesma sessão autenticada porque o servidor nunca regenerou o ID após a autenticação.

How to mitigate

Regenere o ID de sessão imediatamente após um login bem-sucedido. Valide que o IP ou outros atributos da sessão não mudaram drasticamente entre requisições. Use flags Secure, HttpOnly e SameSite nos cookies de sessão para reduzir vetores de ataque.

CVE-2023-50270MEDIUMApache DolphinScheduler: Session do not expire after password changeEPSS 1.3%CVE-2020-25152MEDIUMB. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusEPSS 1.3%CVE-2019-6584A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS EPSS 1.3%CVE-2019-13517In Pyxis ES Versions 1.3.4 through to 1.6.1 and Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12, a vulnerability has EPSS 1.3%CVE-2022-31888HIGHSession Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.EPSS 1.2%CVE-2023-24456CRITICALJenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.EPSS 1.2%CVE-2023-24424HIGHJenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.EPSS 1.2%CVE-2023-45687HIGHAuthentication bypass via session fixation in Titan MFT and Titan SFTP serversEPSS 1.2%CVE-2020-1762HIGHAn insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a reEPSS 1.2%CVE-2018-13282MEDIUMSession fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sEPSS 1.1%CVE-2018-17902Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of sessEPSS 1.1%CVE-2019-0062HIGHJunos OS: Session fixation vulnerability in J-WebEPSS 1.1%CVE-2023-24427CRITICALJenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.EPSS 1.1%CVE-2019-3784HIGHCloud Foundry Stratos contains a Session Collision VulnerabilityEPSS 1.1%CVE-2022-40630MEDIUMImproper Session Management Vulnerability in Tacitine FirewallEPSS 1.0%CVE-2023-3711MEDIUMPotential Predictable Session IDEPSS 1.0%CVE-2022-36437CRITICALThe Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster EPSS 1.0%CVE-2022-22681HIGHSession fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass sEPSS 1.0%CVE-2021-32676MEDIUMSession Fixation in Nextcloud TalkEPSS 1.0%CVE-2022-3916MEDIUMKeycloak: session takeover with oidc offline refreshtokensEPSS 1.0%