Fallos del tipo CWE-384

253 resultados

Fixação de sessão

Ocorre quando a aplicação não regenera o ID da sessão após autenticação bem-sucedida, permitindo que um atacante force um usuário a usar um ID de sessão pré-conhecido. Depois que a vítima se autentica nessa sessão comprometida, o atacante consegue acessar a conta usando o ID que já controla.

Ejemplo

Um atacante envia ao usuário um link com um ID de sessão fixo (ex: PHPSESSID=abc123). A vítima clica, faz login normalmente, mas o servidor nunca muda o ID. Agora o atacante usa a mesma sessão para acessar a conta autenticada, roubando dados ou fazendo transações.

Cómo mitigar

Regenere o ID da sessão imediatamente após login bem-sucedido, descarte o ID antigo, e use um algoritmo criptograficamente forte para gerar novos IDs. Além disso, valide o IP/User-Agent da sessão e implemente timeout de inatividade.

CVE-2024-2260MEDIUMSession Fixation Vulnerability in zenml-io/zenmlEPSS 0.4%CVE-2022-33927MEDIUMDell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by takinEPSS 0.4%CVE-2020-1993LOWPAN-OS: GlobalProtect Portal PHP session fixation vulnerabilityEPSS 0.4%CVE-2023-3192MEDIUMSession Fixation in froxlor/froxlorEPSS 0.4%CVE-2024-11317CRITICALPHP Session FixationEPSS 0.4%CVE-2022-43529MEDIUMA vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persistEPSS 0.4%CVE-2025-59841CRITICALFlagForgeCTF's Improper Session Handling Allows Access After LogoutEPSS 0.4%CVE-2025-45953CRITICALA vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change PassEPSS 0.4%CVE-2021-46279MEDIUMSession Fixation and Insufficient Session ExpirationEPSS 0.4%CVE-2024-56529HIGHMailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when EPSS 0.4%CVE-2025-42602HIGHImproper Authentication Vulnerability in Meon KYC solutionsEPSS 0.4%CVE-2025-28238CRITICALImproper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session EPSS 0.4%CVE-2026-75171CRITICALAn issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.EPSS 0.4%CVE-2024-24823MEDIUMgraylog2-server Session Fixation vulnerability through cookie injectionEPSS 0.4%CVE-2026-43827MEDIUMApache Shiro: Session fixation: new session is not created after login by defaultEPSS 0.4%CVE-2026-33757CRITICALOpenBao lacks user confirmation for OIDC direct callback modeEPSS 0.4%CVE-2025-4644MEDIUMUser Session Fixation after Account Removal in PayloadCMSEPSS 0.4%CVE-2026-86688HIGHSession id is not renewed on authentication in ash_authentication, allowing session fixationEPSS 0.4%CVE-2026-77614HIGHOpencast: Session fixation in login enables account takeover via crafted linkEPSS 0.4%CVE-2023-22479HIGHKubePi vulnerable to session fixation attack EPSS 0.4%