CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
580 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 6 of 12
- CVE-2023-2788MEDIUMCVSS 6.2EG 6.22023-06-16
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's accoun…
- CVE-2023-27891HIGHCVSS 7.5EG 7.52023-03-06
rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.
- CVE-2023-28001MEDIUMCVSS 4.1EG 4.12023-07-11
An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via reusing the session of a deleted user in the REST API.
- CVE-2023-28003MEDIUMCVSS 6.7EG 6.72023-04-18
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
- CVE-2023-30403HIGHCVSS 7.5EG 7.52023-05-02
An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user.
- CVE-2023-31065CRITICALCVSS 9.1EG 9.12023-05-22
Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. An old session can be used by an attacker even after the user has been deleted or the…
- CVE-2023-31139MEDIUMCVSS 4.3EG 4.32023-05-09
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.37 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.1.2, Personal Access Tokens (PATs) generate unrestricted se…
- CVE-2023-31140MEDIUMCVSS 4.8EG 4.82023-05-08
OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a user registers and confirms their first two-factor authentication (2FA) device for an account, existing logged in sessi…
- CVE-2023-32318HIGHCVSS 7.2EG 7.22023-05-26
Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After succes…
- CVE-2023-33005HIGHCVSS 5.4EG 8.82023-05-16
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
- CVE-2023-33303HIGHCVSS 8.1EG 8.12023-10-13
A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request
- CVE-2023-35857CRITICALCVSS 9.8EG 9.82023-06-19
In Siren Investigate before 13.2.2, session keys remain active even after logging out.
- CVE-2023-36252HIGHCVSS 8.8EG 8.82023-06-26
An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function.
- CVE-2023-37504HIGHCVSS 7.1EG 7.12023-10-19
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the ap…
- CVE-2023-37570HIGHCVSS 7.2EG 7.22023-08-08
This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system.
- CVE-2023-37919MEDIUMCVSS 6.5EG 6.52023-07-25
Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain active even after enabling 2FA. When activating 2FA on a Cal.com account that is logged in on two or more devices, the …
- CVE-2023-38489HIGHCVSS 7.3EG 7.32023-07-27
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). It can only be a…
- CVE-2023-39695MEDIUMCVSS 5.3EG 5.32023-10-31
Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and data after logging out.
- CVE-2023-40025MEDIUMCVSS 4.7EG 4.72023-08-23
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open web terminal sessions do not expire. This bug allows users to send any websocket messages e…
- CVE-2023-4005CRITICALCVSS 9.8EG 9.82023-07-31
Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
- CVE-2023-40174MEDIUMCVSS 6.8EG 6.82023-08-18
Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Insufficient session expiration is a web application security vulnerability that occurs when a web application does n…
- CVE-2023-40178MEDIUMCVSS 5.3EG 5.32023-08-23
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOnOrAfter. This could…
- CVE-2023-40537HIGHCVSS 8.1EG 8.12023-10-10
An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform. Note: Software versions which have reached End of Technical Support (…
- CVE-2023-40695MEDIUMCVSS 6.3EG 6.32024-05-03
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 264938.
- CVE-2023-40732LOWCVSS 3.9EG 3.92023-09-12
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking att…
- CVE-2023-41041LOWCVSS 3.1EG 3.12023-08-30
Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged out, a user session may still be used for API requests until it has reached its original expiry time. Each node maintai…
- CVE-2023-4126HIGHCVSS 8.8EG 8.82023-08-03
Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.
- CVE-2023-4190MEDIUMCVSS 6.5EG 6.52023-08-06
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.
- CVE-2023-42768HIGHCVSS 7.2EG 7.22023-10-10
When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can…
- CVE-2023-4320HIGHCVSS 7.5EG 7.52023-12-18
An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage …
- CVE-2023-45187MEDIUMCVSS 6.3EG 6.32024-02-09
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 268749.
- CVE-2023-45600MEDIUMCVSS 5.6EG 5.62024-03-05
A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. This issue affects: AiLux imx6 bundle…
- CVE-2023-45659LOWCVSS 2.8EG 2.82023-10-17
Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained access to a users' account, i.e., logged in and obtained a session, an attackers' session is not terminated if the users' …
- CVE-2023-45718LOWCVSS 3.9EG 3.92024-02-09
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed ou…
- CVE-2023-46158CRITICALCVSS 9.8EG 9.82023-10-25
IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.
- CVE-2023-46326HIGHCVSS 8.8EG 8.82023-11-30
ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.
- CVE-2023-47628MEDIUMCVSS 4.8EG 4.82023-11-14
DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default settings for stateless session which do not set an expiration time for a cookie. Due to this, if a session cookie were e…
- CVE-2023-49091CRITICALCVSS 9.8EG 9.82023-11-29
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Cosmos-server is vulnerable due to to the authorization header used for user login remaining valid an…
- CVE-2023-49881MEDIUMCVSS 6.3EG 6.32025-10-01
IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
- CVE-2023-49935HIGHCVSS 8.8EG 8.82023-12-14
An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integrity Bypass. An attacker can reuse root-level authentication tokens during interaction with the slurmd process…
- CVE-2023-50270MEDIUMCVSS 6.5EG 6.52024-02-20
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.
- CVE-2023-50936MEDIUMCVSS 6.3EG 6.32024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 275116.
- CVE-2023-51772HIGHCVSS 8.8EG 8.82023-12-25
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide th…
- CVE-2023-5838CRITICALCVSS 9.8EG 9.82023-10-29
Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.
- CVE-2023-5865CRITICALCVSS 9.8EG 9.82023-10-31
Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
- CVE-2023-5889HIGHCVSS 8.2EG 8.22023-11-01
Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
- CVE-2024-0008MEDIUMCVSS 6.6EG 6.62024-02-14
Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.
- CVE-2024-0260HIGHCVSS 7.5EG 7.52024-01-07
A vulnerability, which was classified as problematic, was found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file change_password_teacher.php of the component Password Change. The manipulation leads…
- CVE-2024-0350LOWCVSS 3.1EG 3.12024-01-09
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to session expiration. The attack may be launched remot…
- CVE-2024-0942LOWCVSS 3.7EG 3.72024-01-26
A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to…
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →