Falhas do tipo CWE-384

253 resultados

Fixação de Sessão

Fraqueza onde um atacante força a vítima a usar um identificador de sessão conhecido e controlado pelo atacante, em vez de receber um novo ID gerado pela aplicação. Após a vítima autenticar-se, o atacante reutiliza esse ID fixo para acessar a conta com os privilégios da vítima.

Exemplo

Um site envia um cookie de sessão (ex: SESSID=abc123) antes do login. O atacante convence a vítima a acessar um link contendo esse SESSID=abc123, depois que a vítima faz login, o atacante usa o mesmo cookie para acessar a conta autenticada da vítima.

Como mitigar

Gere sempre um novo ID de sessão após autenticação bem-sucedida, descartando qualquer ID anterior. Valide e resete a sessão no servidor a cada mudança de privilégio (login/logout). Use flags seguras no cookie: HttpOnly, Secure e SameSite.

CVE-2025-65681LOWAn issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to seEPSS 0.2%CVE-2026-41839MEDIUMSpring Framework Escalation via Session Fixation in WebFluxEPSS 0.2%CVE-2024-56733MEDIUMPassword Pusher Allows Session Token Interception Leading to Potential HijackingEPSS 0.2%CVE-2024-49709LOWXSS in iKSORISEPSS 0.2%CVE-2026-35095MEDIUMSession fixation in KTM System e-BOKEPSS 0.2%CVE-2025-0251LOWHCL IEM is affected by a concurrent login vulnerabilityEPSS 0.2%CVE-2025-7015MEDIUMSession Hijacking in Akinsoft's QR MenuEPSS 0.2%CVE-2025-0253LOWHCL IEM is affected by a cookie attribute not set vulnerabilityEPSS 0.2%CVE-2021-3740MEDIUMSession Fixation in chatwoot/chatwootEPSS 0.2%CVE-2026-76196HIGHPhotoshop Mobile | Session Fixation (CWE-384)EPSS 0.2%CVE-2025-70973MEDIUMScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not EPSS 0.2%CVE-2023-50920MEDIUMAn issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers EPSS 0.2%CVE-2025-22216MEDIUMCVE-2025-22216 UAA Missing Zone ValidationEPSS 0.2%CVE-2025-36117MEDIUMIBM Db2 Mirror for i session fixationEPSS 0.2%CVE-2026-34454LOWOAuth2 Proxy: Session cookie not cleared when rendering sign-in pageEPSS 0.2%CVE-2026-16089MEDIUMKeycloak-services: keycloak-services: authorization codes can be retargeted to another client sessionEPSS 0.2%CVE-2023-21238—In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local informEPSS 0.2%CVE-2025-56400HIGHCross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya SmarEPSS 0.2%CVE-2026-59883MEDIUMGuzzle: Cookie Disclosure and Injection via IP-Address DomainsEPSS 0.2%CVE-2025-43516LOWA session management issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS TahoeEPSS 0.2%