Fallos del tipo CWE-384

253 resultados

Fixação de sessão

Ocorre quando a aplicação não regenera o ID da sessão após autenticação bem-sucedida, permitindo que um atacante force um usuário a usar um ID de sessão pré-conhecido. Depois que a vítima se autentica nessa sessão comprometida, o atacante consegue acessar a conta usando o ID que já controla.

Ejemplo

Um atacante envia ao usuário um link com um ID de sessão fixo (ex: PHPSESSID=abc123). A vítima clica, faz login normalmente, mas o servidor nunca muda o ID. Agora o atacante usa a mesma sessão para acessar a conta autenticada, roubando dados ou fazendo transações.

Cómo mitigar

Regenere o ID da sessão imediatamente após login bem-sucedido, descarte o ID antigo, e use um algoritmo criptograficamente forte para gerar novos IDs. Além disso, valide o IP/User-Agent da sessão e implemente timeout de inatividade.

CVE-2022-30769MEDIUMSession fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.EPSS 0.5%CVE-2025-45949CRITICALA critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-passwoEPSS 0.5%CVE-2023-5309MEDIUMBroken Session Management in Puppet EnterpriseEPSS 0.5%CVE-2024-13967CRITICALession-Management FailureEPSS 0.5%CVE-2023-53776HIGHScreen SFT DAB 1.9.3 Authentication Bypass via Session Management WeaknessEPSS 0.5%CVE-2026-84652HIGHIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember meEPSS 0.5%CVE-2020-15679HIGHAn OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN userEPSS 0.5%CVE-2023-0897HIGHSession FIxation in Sielco PolyEco1000EPSS 0.5%CVE-2026-33946HIGHMCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID ReplayEPSS 0.5%CVE-2023-52353HIGHAn issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For exampEPSS 0.5%CVE-2026-22082HIGHInsecure Session ID Management Vulnerability in Tenda Wireless RoutersEPSS 0.5%CVE-2024-8643CRITICALSession Hijacking in Oceanic Software's ValeAppEPSS 0.5%CVE-2026-56425CRITICALMISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log InjectionEPSS 0.5%CVE-2024-13279CRITICALTwo-factor Authentication (TFA) - Critical - Access bypass - SA-CONTRIB-2024-043EPSS 0.5%CVE-2022-4231MEDIUMTribal Systems Zenario CMS Remember Me session fixiationEPSS 0.5%CVE-2025-67446CRITICALImproper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictabEPSS 0.5%CVE-2026-12581HIGHDigiwin|EasyFlow .NET - Session FixationEPSS 0.5%CVE-2025-53102HIGHDiscourse's WebAuthn challenge isn't cleared from user session after authenticationEPSS 0.5%CVE-2025-46815HIGHZITADEL Allows IdP Intent Token ReuseEPSS 0.4%CVE-2023-4649MEDIUMSession Fixation in instantsoft/icms2EPSS 0.4%