VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 20 of 31
  • CVE-2021-38986MedMar 1, 2022
    risk 0.35cvss 5.4epss 0.00

    IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 212942.

  • CVE-2022-24332MedFeb 25, 2022
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.

  • CVE-2021-26037MedJul 7, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.

  • CVE-2021-27351MedFeb 19, 2021
    risk 0.35cvss 5.3epss 0.01

    The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session.

  • CVE-2020-4995MedFeb 9, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a user to obtain sensitive information from another users' session. IBM X-Force ID: 192912.

  • CVE-2020-4395MedOct 14, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 179358.

  • CVE-2020-4780MedOct 12, 2020
    risk 0.35cvss 5.3epss 0.01

    OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The purpose of the 'secure' attribute is to prevent cookies from being observed by unauthorized parties. IBM X-Force ID: 189158.

  • CVE-2020-3188MedMay 6, 2020
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of…

  • CVE-2020-9482MedApr 28, 2020
    risk 0.35cvss 6.5epss 0.03

    If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12…

  • CVE-2020-4284MedApr 8, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176207.

  • CVE-2020-1768MedFeb 7, 2020
    risk 0.35cvss 5.4epss 0.01

    The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.

  • CVE-2019-5531MedSep 18, 2019
    risk 0.35cvss 5.4epss 0.01

    VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in…

  • CVE-2019-0015MedJan 15, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections until the device is rebooted. A deleted dynamic VPN connection should be immediately disallowed from establishing new VPN connections. Due to an error in token…

  • CVE-2018-1000814MedDec 20, 2018
    risk 0.35cvss 6.5epss 0.01

    aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry…

  • CVE-2017-3215MedJun 20, 2017
    risk 0.35cvss 5.3epss 0.01

    The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions.

  • CVE-2026-53928MedJun 23, 2026
    risk 0.34cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a password-forgot flow and could be used to mint fresh JWTs even after the user reset their password. passwordChange and passwordReset deleted the user's refresh…

  • CVE-2026-53926MedJun 23, 2026
    risk 0.34cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users service is an empty stub being called from passwordChange, passwordForgot, and passwordReset. OAuth access and refresh tokens were not revoked when the user…

  • CVE-2026-12772MedJun 21, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results in session expiration. The…

  • CVE-2026-44188MedJun 15, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authorization) access token before a…

  • CVE-2025-54547MedOct 29, 2025
    risk 0.34cvss 5.3epss 0.00

    On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired