Weaknesses of type CWE-384

249 results

Fixação de Sessão

É quando um atacante consegue forçar um usuário a usar um ID de sessão conhecido por ele, geralmente reutilizando a mesma sessão antes e depois do login. Depois que a vítima se autentica com aquele ID fixo, o atacante usa o mesmo ID para acessar a conta sem precisar da senha.

Example

Um site gera um cookie de sessão antes do login. O atacante envia um link com esse ID de sessão para a vítima (ex: www.site.com?jsessionid=ATACANTE123), a vítima clica e faz login normalmente, mas o atacante já tem acesso à mesma sessão autenticada porque o servidor nunca regenerou o ID após a autenticação.

How to mitigate

Regenere o ID de sessão imediatamente após um login bem-sucedido. Valide que o IP ou outros atributos da sessão não mudaram drasticamente entre requisições. Use flags Secure, HttpOnly e SameSite nos cookies de sessão para reduzir vetores de ataque.

CVE-2024-30262MEDIUMContao's remember-me tokens will not be cleared after a password changeEPSS 0.5%CVE-2022-30769MEDIUMSession fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.EPSS 0.5%CVE-2023-5309MEDIUMBroken Session Management in Puppet EnterpriseEPSS 0.5%CVE-2024-13967CRITICALession-Management FailureEPSS 0.5%CVE-2023-53776HIGHScreen SFT DAB 1.9.3 Authentication Bypass via Session Management WeaknessEPSS 0.5%CVE-2026-84652HIGHIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember meEPSS 0.5%CVE-2020-15679HIGHAn OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN userEPSS 0.5%CVE-2023-0897HIGHSession FIxation in Sielco PolyEco1000EPSS 0.5%CVE-2026-33946HIGHMCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID ReplayEPSS 0.5%CVE-2023-52353HIGHAn issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For exampEPSS 0.5%CVE-2026-22082HIGHInsecure Session ID Management Vulnerability in Tenda Wireless RoutersEPSS 0.5%CVE-2024-8643CRITICALSession Hijacking in Oceanic Software's ValeAppEPSS 0.5%CVE-2026-56425CRITICALMISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log InjectionEPSS 0.5%CVE-2024-13279CRITICALTwo-factor Authentication (TFA) - Critical - Access bypass - SA-CONTRIB-2024-043EPSS 0.5%CVE-2022-4231MEDIUMTribal Systems Zenario CMS Remember Me session fixiationEPSS 0.5%CVE-2025-67446CRITICALImproper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictabEPSS 0.5%CVE-2026-12581HIGHDigiwin|EasyFlow .NET - Session FixationEPSS 0.5%CVE-2025-53102HIGHDiscourse's WebAuthn challenge isn't cleared from user session after authenticationEPSS 0.5%CVE-2025-46815HIGHZITADEL Allows IdP Intent Token ReuseEPSS 0.4%CVE-2023-4649MEDIUMSession Fixation in instantsoft/icms2EPSS 0.4%