VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 16 of 31
  • CVE-2024-31999HigApr 10, 2024
    risk 0.41cvss 7.4epss 0.01

    @festify/secure-session creates a secure stateless cookie session for Fastify. At the end of the request handling, it will encrypt all data in the session with a secret key and attach the ciphertext as a cookie value with the defined cookie name. After that, the session on the…

  • CVE-2024-21722MedFeb 29, 2024
    risk 0.41cvss 6.3epss 0.01

    The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.

  • CVE-2023-45187MedFeb 9, 2024
    risk 0.41cvss 6.3epss 0.00

    IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 268749.

  • CVE-2023-50936MedFeb 2, 2024
    risk 0.41cvss 6.3epss 0.00

    IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 275116.

  • CVE-2023-38489HigJul 27, 2023
    risk 0.41cvss 7.3epss 0.01

    Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). It can only be abused if a Kirby user is logged in on a…

  • CVE-2023-0041MedJun 5, 2023
    risk 0.41cvss 6.3epss 0.00

    IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-Force ID: 243657.

  • CVE-2022-1155HigMar 30, 2022
    risk 0.41cvss 7.4epss 0.01

    Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

  • CVE-2020-15269HigOct 20, 2020
    risk 0.41cvss 7.4epss 0.01

    In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.

  • CVE-2019-4072MedMay 9, 2019
    risk 0.41cvss 6.3epss 0.01

    IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the application back button users can remain logged in as the current user for a…

  • CVE-2018-5438MedMar 20, 2018
    risk 0.41cvss 6.3epss 0.00

    Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker could reuse the session of a previously logged in user. This vulnerability exists when using ISCV together with an Electronic Medical Record (EMR) system, where…

  • CVE-2026-1842MedFeb 20, 2026
    risk 0.40cvss epss 0.00

    HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access tokens when a refresh token was used. Because refresh tokens have a significantly longer lifetime (default one…

  • CVE-2024-56413MedJan 2, 2025
    risk 0.40cvss 6.1epss 0.00

    Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

  • CVE-2024-20301MedMar 6, 2024
    risk 0.40cvss 6.2epss 0.00

    A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally created trusted…

  • CVE-2024-22543MedFeb 27, 2024
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* URI or via the ExportSettings function.

  • CVE-2023-2788MedJun 16, 2023
    risk 0.40cvss 6.2epss 0.01

    Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.

  • CVE-2020-15220MedJan 13, 2021
    risk 0.40cvss 6.1epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions 2.7.2 and 3.0.0.

  • CVE-2019-3790MedJun 6, 2019
    risk 0.40cvss 6.1epss 0.01

    The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser…

  • CVE-2026-59219HigJul 9, 2026
    risk 0.39cvss 7.1epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels, join-note, and the terminal websocket first-message authentication used decode_token without the…

  • CVE-2026-49229HigJul 7, 2026
    risk 0.39cvss 8.3epss 0.00

    Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, while existing Actual session tokens for the disabled user remain valid. The shared session validation path accepts any…

  • CVE-2026-54321HigJun 23, 2026
    risk 0.39cvss 7.0epss 0.00

    Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox previews that were switched from public to private could remain reachable without authentication for a short period after the change,…