Weaknesses of type CWE-384

253 results

Fixação de Sessão

É quando um atacante consegue forçar um usuário a usar um ID de sessão conhecido por ele, geralmente reutilizando a mesma sessão antes e depois do login. Depois que a vítima se autentica com aquele ID fixo, o atacante usa o mesmo ID para acessar a conta sem precisar da senha.

Example

Um site gera um cookie de sessão antes do login. O atacante envia um link com esse ID de sessão para a vítima (ex: www.site.com?jsessionid=ATACANTE123), a vítima clica e faz login normalmente, mas o atacante já tem acesso à mesma sessão autenticada porque o servidor nunca regenerou o ID após a autenticação.

How to mitigate

Regenere o ID de sessão imediatamente após um login bem-sucedido. Valide que o IP ou outros atributos da sessão não mudaram drasticamente entre requisições. Use flags Secure, HttpOnly e SameSite nos cookies de sessão para reduzir vetores de ataque.

CVE-2023-50176MEDIUMA session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows aEPSS 0.4%CVE-2026-14609MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics session fixiationEPSS 0.4%CVE-2023-53775HIGHScreen SFT DAB 1.9.3 Authentication Bypass via Session Management WeaknessEPSS 0.4%CVE-2025-0126HIGHPAN-OS: Session Fixation Vulnerability in GlobalProtect SAML LoginEPSS 0.4%CVE-2024-24552MEDIUMBludit is Vulnerable to Session FixationEPSS 0.4%CVE-2026-23624MEDIUMGLPI is vulnerable to session stealing on externally authenticated user changeEPSS 0.4%CVE-2023-29020MEDIUMCross site request forgery token fixation in fastify-passportEPSS 0.4%CVE-2026-40010CRITICALApache Wicket: possible session fixation using AuthenticatedWebSessionEPSS 0.4%CVE-2025-29928HIGHauthentik's deletion of sessions did not revoke sessions when using database session storageEPSS 0.4%CVE-2023-38018MEDIUMIBM Aspera Shares session fixationEPSS 0.4%CVE-2025-63529MEDIUMA session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's EPSS 0.4%CVE-2023-34156Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause serEPSS 0.4%CVE-2026-24894HIGHFrankenPHP leaks session data between requests in worker modeEPSS 0.4%CVE-2023-38002MEDIUMIBM Storage Scale session fixationEPSS 0.4%CVE-2009-10007CRITICALCatalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacksEPSS 0.4%CVE-2026-16496HIGHterraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another userEPSS 0.4%CVE-2025-69602CRITICALA session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifierEPSS 0.4%CVE-2020-36913HIGHAll-Dynamics Software enlogic:show 2.0.2 Session Fixation Authentication BypassEPSS 0.4%CVE-2025-53895HIGHZITADEL has broken authN and authZ in session API and resulting session tokensEPSS 0.4%CVE-2023-26260MEDIUMOXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacEPSS 0.4%