Threats Tagged 'cwe-384'
View all threats tagged with 'cwe-384'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-384'
Click on any threat for detailed analysis and mitigation recommendations
0 Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue. Join the discussion | CVE Database V5 | 09/25/2026, 07:44:10 UTC Added: 09/25/2026, 07:48:22 UTC |
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session. Join the discussion | CVE Database V5 | 09/24/2026, 17:27:00 UTC Added: 09/24/2026, 17:48:41 UTC |
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity. Exploitation requires the victim to have completed an OAuth flow in the current session and the deployment to enable auth.google.enabled, auth.github.enabled, or the Slack integration. This issue is fixed in version 0.91.1. Join the discussion | CVE Database V5 | 09/21/2026, 15:45:27 UTC Added: 09/21/2026, 16:02:29 UTC |
0 When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request then executes -- and is recorded in the audit log -- as the cookie's principal rather than the identity the client explicitly presented. Only Apache Airflow 3.3.0 and 3.3.1 are affected. Earlier releases do not contain the code path that caches the cookie-derived user, and are not vulnerable. Exploiting this requires an attacker to first place a valid session cookie of their own into the victim's browser or client: for example by cookie tossing from a sibling subdomain, through cross-site scripting in a separate application sharing a parent domain, or via a shared workstation. Deployments that host the Airflow UI on a domain shared with other applications are therefore the most exposed; a deployment on a dedicated domain with no co-hosted applications is not reachable this way. The consequence is principal confusion and misattributed audit records rather than a direct privilege escalation. Users of 3.3.0 or 3.3.1 should upgrade to Apache Airflow 3.3.2 or later, which resolves the caller from the explicitly supplied credential whenever one is present. Join the discussion | CVE Database V5 | 09/21/2026, 14:32:04 UTC Added: 09/21/2026, 14:47:11 UTC |
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation. An attacker who can obtain an unauthenticated SysReptor session cookie, place it in a victim's browser, and know the shared-note URL where the victim authenticates can reuse the fixed session after the victim enters the correct password and access that shared note. The main SysReptor login flow is not affected. This issue is fixed in version 2026.68. Join the discussion | CVE Database V5 | 09/18/2026, 17:48:53 UTC Added: 09/18/2026, 18:02:20 UTC |
CVE-2026-86688 is a session fixation vulnerability in the team-alembic ash_authentication library. The flaw allows an attacker who can plant a session identifier in a victim's browser to maintain an authenticated session after the victim logs in. This occurs because the library writes the authenticated subject into the existing session without renewing the session identifier, allowing the original identifier to persist through login and logout cycles. This affects versions from 0.2.0 up to but not including 4.15.0, and from 5.0.0-rc.0 up to but not including 5.0.0-rc.14. Join the discussion | CVE Database V5 | 09/17/2026, 21:58:00 UTC Added: 09/17/2026, 22:17:59 UTC |
0 CVE-2026-61592 is a session fixation vulnerability in djust versions prior to 1.0.7. The issue arises because SSE sessions were keyed solely by a client-chosen session_id without binding to the authenticated user, allowing an attacker who obtains a valid session_id to impersonate the victim. This vulnerability is fixed in version 1.0.7 by binding SSE sessions to the owning principal and rejecting cross-principal access. A workaround is to disable the SSE transport. Join the discussion | CVE Database V5 | 09/16/2026, 21:53:33 UTC Added: 09/16/2026, 22:02:45 UTC |
Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above Join the discussion | CVE Database V5 | 09/15/2026, 10:51:41 UTC Added: 09/15/2026, 11:02:26 UTC |
tirreno, a security framework, has a session fixation issue in versions prior to 0.10.0. During authentication, tirreno validates the user's credentials and establishes the authenticated session, but it does not call `session_regenerate_id()` afterward. As a result, the session identifier is not rotated on login, it stays the same before and after authentication. An attacker able to fix a known session identifier in a victim's browser (for example through a network man-in-the-middle position, or a separate cross-site scripting or subdomain cookie-injection issue) could then gain access to the victim's authenticated session. The issue is fixed in v0.10.0. The session identifier is now regenerated on successful authentication, and the previous session is destroyed. There is no configuration-level workaround. Join the discussion | CVE Database V5 | 09/09/2026, 13:42:03 UTC Added: 09/09/2026, 13:52:50 UTC |
Adobe Photoshop Mobile for Android contains a session fixation vulnerability that could allow an attacker to escalate privileges by exploiting a victim's interaction with a malicious webpage. The vulnerability affects versions up to 1.6.0.2299 and requires user interaction. The scope of the vulnerability is changed, indicating a potential impact beyond the initially affected component. Join the discussion | CVE Database V5 | 09/08/2026, 17:27:43 UTC Added: 09/08/2026, 17:38:01 UTC |
Showing 1 to 10 of 53 results