CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
580 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 7 of 12
- CVE-2024-0943LOWCVSS 3.7EG 3.72024-01-26
A vulnerability was found in Totolink N350RT 9.3.5u.6255. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. The a…
- CVE-2024-0944LOWCVSS 3.7EG 3.72024-01-26
A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. The attac…
- CVE-2024-11208LOWCVSS 3.7EG 3.72024-11-14
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. …
- CVE-2024-11627MEDIUMCVSS 6.8EG 6.82025-01-07
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400…
- CVE-2024-11668MEDIUMCVSS 4.2EG 4.22024-11-26
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access…
- CVE-2024-12667LOWCVSS 3.7EG 3.72024-12-16
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched …
- CVE-2024-13280CRITICALCVSS 9.8EG 9.82025-01-09
Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.
- CVE-2024-13996CRITICALCVSS 9.8EG 9.82025-10-30
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained…
- CVE-2024-1623HIGHCVSS 7.7EG 7.72024-03-14
Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without requiring login credentials. This vulnerability is poss…
- CVE-2024-1900MEDIUMCVSS 5.5EG 5.52024-03-05
Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the…
- CVE-2024-20301MEDIUMCVSS 6.2EG 6.22024-03-06
A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to i…
- CVE-2024-21492MEDIUMCVSS 4.8EG 4.82024-02-17
All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User sessions remain valid even after requests …
- CVE-2024-21722MEDIUMCVSS 6.3EG 6.32024-02-29
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
- CVE-2024-22351MEDIUMCVSS 6.3EG 6.32025-04-23
IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
- CVE-2024-22358MEDIUMCVSS 6.3EG 6.32024-04-12
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 does not invalidate session after logout which could allow an authenticated user to …
- CVE-2024-22389HIGHCVSS 7.2EG 7.22024-02-14
When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- CVE-2024-22403LOWCVSS 3.0EG 3.02024-01-18
Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 O…
- CVE-2024-22543MEDIUMCVSS 6.1EG 6.12024-02-27
An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* URI or via the ExportSettings function.
- CVE-2024-23586MEDIUMCVSS 5.3EG 5.32024-09-27
HCL Nomad is susceptible to an insufficient session expiration vulnerability. Under certain circumstances, an unauthenticated attacker could obtain old session information.
- CVE-2024-25051MEDIUMCVSS 6.6EG 6.62025-04-02
IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.
- CVE-2024-25619LOWCVSS 3.1EG 3.12024-02-14
Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the Access Tokens had also been destroyed, this could have posed security r…
- CVE-2024-25628HIGHCVSS 7.6EG 7.62024-02-16
Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the admin area even after being invalidated/deleted. This issue has been addressed in version 2.0-M4-2402. All users are…
- CVE-2024-25718CRITICALCVSS 9.8EG 9.82024-02-11
In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.
- CVE-2024-25954MEDIUMCVSS 5.3EG 5.32024-03-28
Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
- CVE-2024-27455CRITICALCVSS 9.1EG 9.12024-02-26
In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integ…
- CVE-2024-27779MEDIUMCVSS 6.7EG 6.72025-07-18
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all…
- CVE-2024-27782HIGHCVSS 8.1EG 8.12024-07-09
Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.
- CVE-2024-29070CRITICALCVSS 9.1EG 9.12024-07-23
On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests a…
- CVE-2024-29401CRITICALCVSS 9.8EG 9.82024-03-26
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
- CVE-2024-29402MEDIUMCVSS 4.3EG 4.32024-04-16
cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious activity.
- CVE-2024-30262MEDIUMCVSS 5.9EG 5.92024-04-09
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone …
- CVE-2024-31447MEDIUMCVSS 5.3EG 5.32024-04-08
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST /store-api/account/logout`, the cart will be c…
- CVE-2024-31995MEDIUMCVSS 4.3EG 4.32024-04-10
`@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.1, when invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `ex…
- CVE-2024-31999HIGHCVSS 7.4EG 7.42024-04-10
@festify/secure-session creates a secure stateless cookie session for Fastify. At the end of the request handling, it will encrypt all data in the session with a secret key and attach the ciphertext as a cookie value with the defined cooki…
- CVE-2024-32006MEDIUMCVSS 4.3EG 4.32024-09-10
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the user session on reboot without logout. This could allow an attacker to bypass Multi-Factor Authenti…
- CVE-2024-33507HIGHCVSS 7.4EG 7.42025-10-14
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism ma…
- CVE-2024-34092HIGHCVSS 8.8EG 8.82024-05-06
An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is also a fixed release.
- CVE-2024-34709MEDIUMCVSS 5.4EG 5.42024-05-14
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens function like the other JWT tokens where they are not actually invalidated when logging out. The `directus_session` gets dest…
- CVE-2024-35048MEDIUMCVSS 4.3EG 4.32024-05-14
An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.
- CVE-2024-35049CRITICALCVSS 9.1EG 9.12024-05-14
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.
- CVE-2024-35050HIGHCVSS 8.8EG 8.82024-05-14
An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.
- CVE-2024-35160MEDIUMCVSS 4.3EG 4.32024-11-23
IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7.6 could allow an authenticated user to obtain sensitive information due to insufficient session expiration.
- CVE-2024-35206HIGHCVSS 7.7EG 7.82024-06-11
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application does not expire the session. This could allow an attacker to get unauthorized access.
- CVE-2024-35220HIGHCVSS 7.4EG 7.42024-05-21
@fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from the session store, the `expires` field is overriden if the `maxAge` field was set. This means a cookie is never correctly…
- CVE-2024-36041HIGHCVSS 7.8EG 7.82024-07-05
KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections are accepted. This allows another user on the same machine to…
- CVE-2024-36523MEDIUMCVSS 6.5EG 6.52024-06-12
An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after deleting their own or administrator accounts. This is provided that the users do not log out of their deleted accounts.
- CVE-2024-38315MEDIUMCVSS 6.3EG 6.32024-09-16
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
- CVE-2024-39809HIGHCVSS 7.5EG 7.52024-08-14
The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- CVE-2024-41827HIGHCVSS 7.4EG 7.42024-07-22
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
- CVE-2024-41985LOWCVSS 2.6EG 2.62025-08-12
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not exp…
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →