目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-384 会话固定 类漏洞列表 184

CWE-384 会话固定 类弱点 184 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-384 会话固定是一种身份验证漏洞,指系统在用户认证后未销毁旧会话标识符,导致攻击者可利用预设的会话ID劫持合法会话。攻击者通常诱导受害者使用其控制的会话ID进行登录,从而窃取权限。开发者应避免此问题,需在用户成功认证或权限变更后强制生成新的会话标识符,并彻底销毁旧会话,确保会话状态与用户身份严格绑定。

MITRE CWE 官方描述
CWE:CWE-384 Session Fixation(会话固定) 在验证用户身份或建立新的用户会话时,如果不使任何现有的会话标识符(Session Identifier)失效,攻击者便有机会窃取已认证的会话。 通常会在以下场景中观察到此类情况:Web 应用在未首先使现有会话失效的情况下对用户进行身份验证,从而继续使用已与用户关联的会话。攻击者能够强制用户接受一个已知的会话标识符,以便在用户完成身份验证后,攻击者即可访问该已认证的会话。应用程序或容器使用可预测的会话标识符。在针对会话固定漏洞的通用利用中,攻击者在 Web 应用中创建一个新会话并记录相关的会话标识符。随后,攻击者诱导受害者使用该会话标识符与服务器建立关联(并可能进行身份验证),从而使攻击者能够通过该活动会话访问用户的账户。
常见影响 (1)
Access Control Gain Privileges or Assume Identity
缓解措施 (3)
Architecture and Design Invalidate any existing session identifiers prior to authorizing a new user session.
Architecture and Design For platforms such as ASP that do not generate new values for sessionid cookies, utilize a secondary cookie. In this approach, set a secondary cookie on the user's browser to a random value and set a session variable to the same value. If the session variable and the cookie value ever don't match, invalidate the session, and force the user to log on again.
Operation Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].
Effectiveness: Moderate
代码示例 (2)
The following example shows a snippet of code from a J2EE web application where the application authenticates users with LoginContext.login() without first calling HttpSession.invalidate().
private void auth(LoginContext lc, HttpSession session) throws LoginException { ... lc.login(); ... }
Bad · Java
The following example shows a snippet of code from a J2EE web application where the application authenticates users with a direct post to the <code>j_security_check</code>, which typically does not invalidate the existing session before processing the login request.
<form method="POST" action="j_security_check"> <input type="text" name="j_username"> <input type="text" name="j_password"> </form>
Bad · HTML
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-107229 AsyncHttpClient 默认cookie存储源检查不全导致注入 — async-http-client 4.0 Medium 2026-10-07
CVE-2026-92414 Apache Jackrabbit 通过可推导的 WebDAV 锁令牌劫持缓存会话 — Apache Jackrabbit 9.3 Critical 2026-10-07
CVE-2026-105233 Food Waste Management System login.php 会话固定漏洞 — food-waste-management-system 6.3 Medium 2026-10-05
CVE-2026-104469 YesWiki 4.6.7之前版本 登录会话固定漏洞 — yeswiki 6.8 Medium 2026-10-02
CVE-2026-71302 Toptech TMS7和TopHAT会话固定漏洞 — TMS7 7.1 High 2026-09-29
CVE-2026-92609 Apache Qpid Broker-J 认证后缺少HTTP会话更新漏洞 — Apache Qpid Broker-J - - 2026-09-25
CVE-2026-57179 social-auth-core 会话固定漏洞 — social-core 4.2 Medium 2026-09-24
CVE-2026-95828 Mstfakts大学管理系统会话固定漏洞 — College-Management-System 4.3 Medium 2026-09-22
CVE-2026-82355 Airflow会话Cookie覆盖Bearer头致会话固定 — Apache Airflow - - 2026-09-21
CVE-2026-81181 SysReptor 受密码保护的共享笔记会话固定漏洞 — sysreptor 3.7 Low 2026-09-18
CVE-2026-86688 ash_authentication 会话固定漏洞 — ash_authentication 7.4 High 2026-09-17
CVE-2026-77614 Opencast 登录会话固定导致账户接管漏洞 — opencast 8.8 High 2026-09-17
CVE-2026-92984 HUBzero CMS 2.2.32 会话固定漏洞 — hubzero-cms 8.1 High 2026-09-17
CVE-2026-61592 djust SSE 会话未绑定认证用户漏洞 — djust 7.4 High 2026-09-16
CVE-2026-69214 http4s 会话机制问题漏洞 — http4s 6.8 Medium 2026-09-15
CVE-2026-1758 Session Fixation 会话固定漏洞 — GateManager 8.3 High 2026-09-15
CVE-2026-64857 tirrenotechnologies tirreno 会话机制问题漏洞 — tirreno 5.3 Medium 2026-09-09
CVE-2026-86674 mrning Student Management System 会话机制问题漏洞 — Student Management System 6.3 Medium 2026-09-08
CVE-2026-76196 Adobe Photoshop Android 会话机制问题漏洞 — Photoshop Android 7.4 High 2026-09-08
CVE-2026-86279 SourceCodester Syllabus-Aligned Learning Management & Examination System 会话机制问题漏洞 — Syllabus-Aligned Learning Management & Examination System 6.3 Medium 2026-09-07
CVE-2026-85238 MISP 会话机制问题漏洞 — misp 7.6 High 2026-09-03
CVE-2026-18527 IBM administration runtime expert for i 会话机制问题漏洞 — Administration Runtime Expert for i 9.9 Critical 2026-08-28
CVE-2026-70594 TryGhost Ghost 会话机制问题漏洞 — Ghost 6.7 Medium 2026-08-04
CVE-2026-16496 HashiCorp Tooling 会话机制问题漏洞 — Tooling 8.9 High 2026-07-28
CVE-2026-14609 SourceCodester CET Automated Grading System with AI Predictive Analytics 会话机制问题漏洞 — CET Automated Grading System with AI Predictive Analytics 5.6 Medium 2026-07-03
CVE-2026-13707 Wikimedia OAuth 会话机制问题漏洞 — OAuth - - 2026-07-01
CVE-2026-56224 Capgo 会话机制问题漏洞 — Capgo 5.4 Medium 2026-06-30
CVE-2026-35095 KTM System e-BOK 会话机制问题漏洞 — e-BOK - - 2026-06-30
CVE-2026-40082 Cacti 会话机制问题漏洞 — cacti 5.4 Medium 2026-06-25
CVE-2026-56425 MISP 会话机制问题漏洞 — misp - - 2026-06-22

CWE-384(会话固定) 是常见的弱点类别,本平台收录该类弱点关联的 184 条 CVE 漏洞。