CVEbaza.plSłownik CWECWE-488
Common Weakness Enumeration

CWE-488

Exposure of Data Element to Wrong Session

Kategoria: BaseCVE: 36
Opis

Produkt nie egzekwuje wystarczająco granic między stanami różnych sesji, co powoduje, że dane są dostarczane do lub używane przez błędną sesję. To stanowi zagrożenie bezpieczeństwa, ponieważ może doprowadzić do nieautoryzowanego dostępu do poufnych informacji.

Description (EN)

The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.

Podatności CVE z CWE-488 (36)
10.0
CVSS
CRITICAL
CVE-2026-16326

Podatność w consul-mcp-server (wersje 0.1.0–0.1.3) umożliwia nieprawidłową izolację stanu sesji w trybie bezstanowym (stateless), przez co token uwierzytelniający Consul jednego klienta może zostać użyty do obsługi żądań innych klientów. Jest to krytyczna luka, ponieważ może prowadzić do nieautoryzowanego dostępu do zasobów Consul z uprawnieniami innego użytkownika.

pub. 2026-07-29
10.0
CVSS
CRITICAL
CVE-2026-16498

Podatność w terraform-mcp-server przed wersją 1.1.0 umożliwia ponowne użycie tokenu Terraform jednego użytkownika do wykonywania wywołań narzędzi w imieniu kolejnych użytkowników. Problem dotyczy trybu bezstanowego transportu streamable-HTTP i może prowadzić do nieautoryzowanego dostępu między dzierżawcami (cross-tenant).

pub. 2026-07-28
9.1
CVSS
CRITICAL
CVE-2025-47928

Biblioteka Spotipy zawierała podatny workflow GitHub Actions wykorzystujący `pull_request_target`, który umożliwiał wykonanie niezaufanego kodu z pełnym dostępem do sekretów repozytorium bazowego. Błąd pozwalał atakującemu na przejęcie kontroli nad repozytorium poprzez eksfiltrację tokenu `GITHUB_TOKEN` z uprawnieniami zapisu.

pub. 2025-05-15
9.1
CVSS
CRITICAL
CVE-2024-27455

Podatność w aplikacji webowej Bentley ALIM Web powoduje ujawnienie tokenu sesji użytkownika podczas próby pobrania plików. Atakujący może przejąć sesję ofiary i uzyskać nieautoryzowany dostęp do systemu bez jakiegokolwiek uwierzytelnienia.

pub. 2024-02-26
8.3
CVSS
HIGH
CVE-2025-1247

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.

pub. 2025-02-13
8.2
CVSS
HIGH
CVE-2024-38367

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab449af9a56a21ab40697b9f7b97, the trunk sessions verification step could be manipulated for owner session hijacking Compromising a victim’s session will result in a full takeover of the CocoaPods trunk account. The threat actor could manipulate their pod specifications, disrupt the distribution of legitimate libraries, or cause widespread disruption within the CocoaPods ecosystem. This was patched server-side with commit d4fa66f49cedab449af9a56a21ab40697b9f7b97 in October 2023.

pub. 2024-07-01
8.0
CVSS
HIGH
CVE-2023-1907

A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection attempts occur simultaneously.

pub. 2025-01-09
7.5
CVSS
HIGH
CVE-2025-15576

If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may nonetheless be able to access a shared directory via a nullfs mount, if the administrator has configured one. In this case, cooperating processes in the two jails may establish a connection using a unix domain socket and exchange directory descriptors with each other. When performing a filesystem name lookup, at each step of the lookup, the kernel checks whether the lookup would descend below the jail root of the current process. If the jail root directory is not encountered, the lookup continues. In a configuration where processes in two different jails are able to exchange file descriptors using a unix domain socket, it is possible for a jailed process to receive a directory for a descriptor that is below that process' jail root. This enables full filesystem access for a jailed process, breaking the chroot. Note that the system administrator is still responsible for ensuring that an unprivileged user on the jail host is not able to pass directory descriptors to a jailed process, even in a patched kernel.

pub. 2026-03-09
7.5
CVSS
HIGH
CVE-2025-30073

An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0. The reference assigned to transactions can be reused. When completing a payment, the first or all transactions with the same reference are completed, depending on timing. This can be used to transfer more money onto employee cards than is paid.

pub. 2025-03-26
7.5
CVSS
HIGH
CVE-2024-5148

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.

pub. 2024-09-02
7.5
CVSS
HIGH
CVE-2024-6162

A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.

pub. 2024-06-20
7.5
CVSS
HIGH
CVE-2023-6519

Exposure of Data Element to Wrong Session vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Executable. This issue affects MİA-MED: before 1.0.7.

pub. 2024-02-08
7.4
CVSS
HIGH
CVE-2026-18489

IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.

pub. 2026-09-04
7.3
CVSS
HIGH
CVE-2024-41977

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1 ADSL-Router family (All versions < V8.1), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.1), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2) (All versions < V8.1), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.1), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.1), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.1), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.1), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1) (All versions < V8.1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1) (All versions < V8.1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1) (All versions < V8.1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1) (All versions < V8.1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1) (All versions < V8.1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.1), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.1). Affected devices do not properly enforce isolation between user sessions in their web server component. This could allow an authenticated remote attacker to escalate their privileges on the devices.

pub. 2024-08-13
7.2
CVSS
HIGH
CVE-2024-27935

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to version 1.36.3, a vulnerability in Deno's Node.js compatibility runtime allows for cross-session data contamination during simultaneous asynchronous reads from Node.js streams sourced from sockets or files. The issue arises from the re-use of a global buffer (BUF) in stream_wrap.ts used as a performance optimization to limit allocations during these asynchronous read operations. This can lead to data intended for one session being received by another session, potentially resulting in data corruption and unexpected behavior. This affects all users of Deno that use the node.js compatibility layer for network communication or other streams, including packages that may require node.js libraries indirectly. Version 1.36.3 contains a patch for this issue.

pub. 2024-03-21
7.1
CVSS
HIGH
CVE-2026-23919

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information <a href='https://www.zabbix.com/documentation/7.4/en/manual/installation/known_issues#preprocessing-global-variables-are-unsafe'>in Zabbix documentation</a>.

pub. 2026-03-24
6.8
CVSS
MEDIUM
CVE-2026-54497

view_component to framework do budowania wielokrotnego użytku, testowalnych i enkapsulowanych komponentów widoku w Ruby on Rails. W wersjach od 4.0.0 do 4.12.0 instancje ViewComponent::Base zachowują obiekty przypisane do zakresu render across multiple calls do render_in; jeśli ta sama instancja komponentu, kolekcji lub spacer komponentu jest ponownie użyta across requests, użytkowników, dzierżawców lub wątków, późniejsze rendering mogą korzystać z nieaktualnych helpers, controllera, request, view_flow, format/variant detali i slot child context z wcześniejszego renderowania. Może to spowodować, że komponenty świadome autoryzacji renderują uprzywilejowany UI dla użytkownika z niższymi uprawnieniami, generują linki przy użyciu nieaktualnego nagłówka Host, ujawniają stan slot/helper i mieszają kontekst request podczas równoczesnego renderowania. Problem został naprawiony w wersji 4.12.0.

pub. 2026-07-17
6.8
CVSS
MEDIUM
CVE-2022-40210

Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

pub. 2023-05-10
6.6
CVSS
MEDIUM
CVE-2026-34391

Fleet to oprogramowanie open source do zarządzania urządzeniami. Przed wersją 4.81.1 podatność w przetwarzaniu poleceń Windows MDM w Fleet umożliwia złośliwemu zarejestrowanemu urządzeniu dostęp do poleceń MDM przeznaczonych dla innych urządzeń, potencjalnie ujawniając wrażliwe dane konfiguracyjne, takie jak poświadczenia WiFi, sekrety VPN i payloady certyfikatów na całej floty Windows. Wersja 4.81.1 naprawia ten problem.

pub. 2026-03-27
6.5
CVSS
MEDIUM
CVE-2026-33215

NATS-Server to wysoko wydajny serwer dla NATS.io, natywnego dla chmury i edge'u systemu komunikatów. Serwer nats-server udostępnia interfejs klienta MQTT. Przed wersjami 2.11.15 i 2.12.5 sesje i wiadomości mogły być przejęte poprzez niewłaściwe użycie identyfikatora klienta MQTT. Wersje 2.11.15 i 2.12.5 usuwają tę lukę. Nie są dostępne znane obejścia.

pub. 2026-03-24
Pokazano 20 z 36 podatności
Informacje
ID: CWE-488
Typ: Base
Podatności: 36
MITRE CWE ↗
← Słownik CWE