Skip to main content

CWE archive

CWE-384 CVEs

Programmatic archive

414 CVEs tagged with CWE-38472 Critical, 150 High, 164 Medium, 27 Low, 1 Unrated.

CVE-2023-40273

Published Aug 23, 2023

The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up unti…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-21239

Published Jul 13, 2023

In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21238

Published Jul 13, 2023

In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional exe…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37946

Published Jul 12, 2023

Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34156

Published Jun 19, 2023

Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause services to be denied.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32997

Published May 16, 2023

Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31498

Published May 11, 2023

A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28316

Published May 9, 2023

A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-1265

Published May 3, 2023

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 b…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29020

Published Apr 21, 2023

@fastify/passport is a port of passport authentication library for the Fastify ecosystem. The CSRF (Cross-Site Request Forger) protection enforced by the `@fastify/csrf-protection…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29019

Published Apr 21, 2023

@fastify/passport is a port of passport authentication library for the Fastify ecosystem. Applications using `@fastify/passport` in affected versions for user authentication, in c…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26260

Published Apr 11, 2023

OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the us…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31888

Published Apr 5, 2023

Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27490

Published Mar 9, 2023

NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subje…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36394

Published Mar 6, 2023

In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-42761

Published Feb 16, 2023

A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24895

Published Feb 3, 2023

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon logi…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 414 CVEsPage 7 of 17