CWE-384 会话固定 类弱点 145 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-384 会话固定是一种身份验证漏洞,指系统在用户认证后未销毁旧会话标识符,导致攻击者可利用预设的会话ID劫持合法会话。攻击者通常诱导受害者使用其控制的会话ID进行登录,从而窃取权限。开发者应避免此问题,需在用户成功认证或权限变更后强制生成新的会话标识符,并彻底销毁旧会话,确保会话状态与用户身份严格绑定。
private void auth(LoginContext lc, HttpSession session) throws LoginException { ... lc.login(); ... }<form method="POST" action="j_security_check"> <input type="text" name="j_username"> <input type="text" name="j_password"> </form>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-0251 | HCL Connections 安全漏洞 — IEM | 2.6 | Low | 2025-07-25 |
| CVE-2025-36117 | IBM Db2 Mirror for i 授权问题漏洞 — Db2 Mirror for i | 6.3 | Medium | 2025-07-23 |
| CVE-2025-52689 | Alcatel-Lucent OmniAccess Stellar Products 安全漏洞 — OmniAccess Stellar Products | 9.8 | Critical | 2025-07-16 |
| CVE-2025-53021 | Moodle 授权问题漏洞 — Moodle | 4.2 | Medium | 2025-06-24 |
| CVE-2024-13967 | BAB TECHNOLOGIE EIBPORT V3 授权问题漏洞 — EIBPORT V3 KNX | 8.8 | High | 2025-06-04 |
| CVE-2024-49709 | SoftCOM iKSORIS 授权问题漏洞 — iKSORIS | 8.8AI | HighAI | 2025-04-14 |
| CVE-2025-0126 | Palo Alto Networks PAN-OS 安全漏洞 — Cloud NGFW | 8.8AI | HighAI | 2025-04-11 |
| CVE-2025-29928 | authentik 授权问题漏洞 — authentik | 8.0 | High | 2025-03-28 |
| CVE-2025-26658 | SAP Business One 授权问题漏洞 — SAP Business One (Service Layer) | 6.8 | Medium | 2025-03-11 |
| CVE-2025-1412 | Mattermost 安全漏洞 — Mattermost | 3.1 | Low | 2025-02-24 |
| CVE-2024-49344 | IBM OpenPages with Watson 授权问题漏洞 — OpenPages with Watson | 4.3 | Medium | 2025-02-20 |
| CVE-2024-42207 | HCL iAutomate 安全漏洞 — iAutomate | 5.5 | Medium | 2025-02-05 |
| CVE-2024-42171 | HCL DRYiCE MyXalytics 安全漏洞 — DRYiCE MyXalytics | 6.4 | Medium | 2025-01-11 |
| CVE-2024-42170 | HCL DRYiCE MyXalytics 安全漏洞 — DRYiCE MyXalytics | 6.8 | Medium | 2025-01-11 |
| CVE-2024-13279 | Drupal 安全漏洞 — Two-factor Authentication (TFA) | 7.1 | - | 2025-01-09 |
| CVE-2024-56733 | Password Pusher 授权问题漏洞 — PasswordPusher | 5.7 | Medium | 2024-12-30 |
| CVE-2024-28144 | Image Access Scan2Net 安全漏洞 — Scan2Net | 9.8 | - | 2024-12-12 |
| CVE-2024-11317 | ABB ASPECT 安全漏洞 — ASPECT-Enterprise | 10.0 | Critical | 2024-12-05 |
| CVE-2021-3740 | Chatwoot 授权问题漏洞 — chatwoot/chatwoot | 7.1AI | HighAI | 2024-11-15 |
| CVE-2023-50176 | Fortinet FortiOS 授权问题漏洞 — FortiOS | 7.1 | High | 2024-11-12 |
| CVE-2024-10318 | F5 Nginx 安全漏洞 — NGINX OpenID Connect | 5.4 | Medium | 2024-11-06 |
| CVE-2024-23590 | Apache Kylin 授权问题漏洞 — Apache Kylin | 9.8AI | CriticalAI | 2024-11-04 |
| CVE-2024-48929 | Umbraco CMS 授权问题漏洞 — Umbraco-CMS | 4.2 | Medium | 2024-10-22 |
| CVE-2024-10158 | PHPGurukul Boat Booking System 安全漏洞 — Boat Booking System | 4.3 | Medium | 2024-10-19 |
| CVE-2024-8643 | ValeApp 安全漏洞 — ValeApp | 8.8AI | HighAI | 2024-09-27 |
| CVE-2024-45368 | AutomationDirect DirectLogic H2-DM1E 授权问题漏洞 — DirectLogic H2-DM1E | 8.8 | High | 2024-09-13 |
| CVE-2024-42345 | Siemens SINEMA Remote Connect Server 授权问题漏洞 — SINEMA Remote Connect Server | 4.3 | Medium | 2024-09-10 |
| CVE-2024-7341 | Red Hat Keycloak 授权问题漏洞 | 7.1 | High | 2024-09-09 |
| CVE-2023-38018 | IBM Aspera Shares 授权问题漏洞 — Aspera Shares | 6.3 | Medium | 2024-08-09 |
| CVE-2024-38513 | Fiber 安全漏洞 — fiber | 10.0 | Critical | 2024-07-01 |
CWE-384(会话固定) 是常见的弱点类别,本平台收录该类弱点关联的 145 条 CVE 漏洞。