VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 19 of 31
  • CVE-2026-5545MedMay 13, 2026
    risk 0.35cvss 6.5epss 0.00

    libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subsequent requests can reuse an existing…

  • CVE-2026-44873MedMay 12, 2026
    risk 0.35cvss 5.4epss 0.00

    A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration.…

  • CVE-2026-25720MedApr 24, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allowing authenticated sessions to remain active for extended periods without requiring re-authentication. An attacker with access to a previously authenticated…

  • CVE-2026-6515MedApr 22, 2026
    risk 0.35cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.

  • CVE-2026-6848MedApr 22, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with…

  • CVE-2026-40587MedApr 21, 2026
    risk 0.35cvss 6.5epss 0.00

    blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their password via the profile edit page, or when a password reset is completed via the reset link, neither operation invalidates existing authenticated sessions for that user. A…

  • CVE-2026-35594MedApr 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing.go) constructs authorization objects entirely from JWT claims without any server-side database validation. When…

  • CVE-2026-33417MedMar 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The password_resets table includes a created_at timestamp column, but the token validation logic never checks it. A password reset token…

  • CVE-2026-28396MedMar 2, 2026
    risk 0.35cvss 6.5epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not revoke existing refresh tokens, allowing an attacker with a previously stolen refresh token to continue minting valid JWTs after the victim resets their password.…

  • CVE-2025-43819MedSep 24, 2025
    risk 0.35cvss 6.5epss 0.00

    A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated…

  • CVE-2025-10223MedSep 10, 2025
    risk 0.35cvss 5.4epss 0.00

    Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural…

  • CVE-2025-58352MedSep 5, 2025
    risk 0.35cvss 6.5epss 0.00

    Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in…

  • CVE-2024-57056MedFeb 18, 2025
    risk 0.35cvss 5.4epss 0.00

    Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to system logs and could be used by a malicious attacker to impersonate an existing user session.

  • CVE-2023-50270MedFeb 20, 2024
    risk 0.35cvss 6.5epss 0.01

    Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.

  • CVE-2023-4190MedAug 6, 2023
    risk 0.35cvss 6.5epss 0.01

    Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.

  • CVE-2023-33005MedMay 16, 2023
    risk 0.35cvss 5.4epss 0.00

    Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.

  • CVE-2023-0227MedJan 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.

  • CVE-2022-47406MedDec 14, 2022
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x before 3.0.3, for TYPO3. The extension fails to revoke existing sessions for the current user when the password has been changed.

  • CVE-2022-41542MedOct 17, 2022
    risk 0.35cvss 5.4epss 0.01

    devhub 0.102.0 was discovered to contain a broken session control.

  • CVE-2022-31145MedJul 13, 2022
    risk 0.35cvss 6.5epss 0.01

    FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. In versions 1.1.30 and prior, authenticated users using an external identity provider can continue to use Access Tokens and ID Tokens even after they expire. Users…