CWE-613— Insufficient Session Expiration
485 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 2 of 10
- CVE-2019-9269HIGHCVSS 7.3EG 7.32019-09-27
In System Settings, there is a possible permissions bypass due to a cached Linux user ID. This could lead to a local permissions bypass with no additional execution privileges needed. User interaction is needed for exploitation. Product: A…
- CVE-2020-0621MEDIUMCVSS 4.4EG 4.42020-01-14
A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'.
- CVE-2020-10709HIGHCVSS 7.1EG 7.12021-05-27
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that does not expire. The…
- CVE-2020-10876HIGHCVSS 7.5EG 7.52020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excess…
- CVE-2020-11688HIGHCVSS 7.5EG 7.52020-04-22
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
- CVE-2020-11795HIGHCVSS 7.5EG 7.52020-04-22
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
- CVE-2020-12690HIGHCVSS 8.8EG 8.82020-05-07
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains…
- CVE-2020-13299HIGHCVSS 8.1EG 8.12020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.
- CVE-2020-13302LOWCVSS 3.8EG 3.82020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.
- CVE-2020-13305LOWCVSS 3.5EG 3.52020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upon removing a user from a project.
- CVE-2020-13307LOWCVSS 3.8EG 3.82020-09-15
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.
- CVE-2020-13353LOWCVSS 2.5EG 2.52020-11-17
When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.
- CVE-2020-14247MEDIUMCVSS 6.5EG 6.52021-02-04
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.
- CVE-2020-15074HIGHCVSS 7.5EG 7.52020-07-14
OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.
- CVE-2020-15218MEDIUMCVSS 6.8EG 6.82021-01-13
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 …
- CVE-2020-15220MEDIUMCVSS 6.1EG 6.12021-01-13
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions 2.7.2 and 3.0.0.
- CVE-2020-15269HIGHCVSS 7.4EG 7.42020-10-20
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linke…
- CVE-2020-15774MEDIUMCVSS 6.8EG 6.82020-09-18
An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in to Gradle Enterprise and since closed their browser could reopen their browser to access G…
- CVE-2020-15950HIGHCVSS 8.8EG 8.82020-11-05
Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
- CVE-2020-1666MEDIUMCVSS 6.6EG 6.62020-10-16
The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access …
- CVE-2020-1724MEDIUMCVSS 4.3EG 4.32020-05-11
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
- CVE-2020-17473MEDIUMCVSS 5.9EG 5.92020-08-14
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.
- CVE-2020-17474CRITICALCVSS 9.8EG 9.82020-08-14
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.
- CVE-2020-1762HIGHCVSS 7.0EG 7.02020-04-27
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user s…
- CVE-2020-1768MEDIUMCVSS 5.4EG 5.42020-02-07
The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.
- CVE-2020-1776LOWCVSS 3.5EG 4.32020-07-20
When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not be used to access ticket data in the case the agent is invalid. This issue affects ((OTRS)) Community Edition: 6.0.28 an…
- CVE-2020-23136MEDIUMCVSS 5.5EG 5.52020-11-09
Microweber v1.1.18 is affected by no session expiry after log-out.
- CVE-2020-23140HIGHCVSS 8.1EG 8.12020-11-09
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
- CVE-2020-24387HIGHCVSS 7.5EG 7.52020-10-19
An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write op…
- CVE-2020-24713HIGHCVSS 7.5EG 7.52020-10-28
Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
- CVE-2020-25374LOWCVSS 2.6EG 2.62020-10-28
CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.
- CVE-2020-27416CRITICALCVSS 9.8EG 9.82021-12-08
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.
- CVE-2020-27422CRITICALCVSS 9.8EG 9.82020-11-16
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
- CVE-2020-27739CRITICALCVSS 9.8EG 9.82020-10-28
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vul…
- CVE-2020-29012MEDIUMCVSS 5.6EG 5.62021-09-08
An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information about other users configured on the device, should the attack…
- CVE-2020-29667CRITICALCVSS 9.8EG 9.82020-12-10
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
- CVE-2020-3188MEDIUMCVSS 5.3EG 5.32020-05-06
A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected dev…
- CVE-2020-35358CRITICALCVSS 9.8EG 9.82021-03-15
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. …
- CVE-2020-4253HIGHCVSS 8.8EG 8.82020-03-24
IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559.
- CVE-2020-4284MEDIUMCVSS 5.3EG 5.32020-04-08
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176207.
- CVE-2020-4395MEDIUMCVSS 5.4EG 5.42020-10-14
IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 179358.
- CVE-2020-4696MEDIUMCVSS 4.3EG 4.32020-11-30
IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session. IBM X-Force ID: 186789.
- CVE-2020-4780MEDIUMCVSS 5.3EG 5.32020-10-12
OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The purpose of the 'secure' attribute is to prevent cookies from being observed by unauthorized p…
- CVE-2020-4914MEDIUMCVSS 4.2EG 4.22023-05-05
IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290.
- CVE-2020-4995MEDIUMCVSS 5.3EG 5.32021-02-09
IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a user to obtain sensitive information from another users' session. IBM X-Force ID: 192912.
- CVE-2020-5774HIGHCVSS 7.1EG 7.12020-08-21
Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios. The lack of proper session expiration could allow attackers with local access to login into an existing browser sessi…
- CVE-2020-6178MEDIUMCVSS 5.4EG 5.42020-03-10
SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.
- CVE-2020-6197LOWCVSS 3.3EG 3.32020-03-10
SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.
- CVE-2020-6291HIGHCVSS 8.8EG 8.82020-07-14
SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration
- CVE-2020-6292HIGHCVSS 8.8EG 8.82020-07-14
Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →