VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 23 of 31
  • CVE-2020-6363MedOct 15, 2020
    risk 0.30cvss 4.6epss 0.01

    SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credentials. The user can change their own passphrase, but this…

  • CVE-2025-48061MedMay 22, 2025
    risk 0.29cvss 5.6epss 0.00

    wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logged in again after re-opening the…

  • CVE-2021-27751MedMay 6, 2022
    risk 0.29cvss 4.4epss 0.00

    HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.

  • CVE-2019-5647MedJan 22, 2020
    risk 0.29cvss 4.4epss 0.00

    The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijacking attempts easier, since the user could believe a session was closed when it…

  • CVE-2020-0621MedJan 14, 2020
    risk 0.29cvss 4.4epss 0.01

    A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'.

  • CVE-2019-14826MedSep 17, 2019
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

  • CVE-2026-9162MedJun 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connections during global session revocation, which allows a user with an existing WebSocket connection to remain…

  • CVE-2026-42421MedApr 28, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway token rotation. Attackers can maintain unauthorized access to WebSocket connections after token rotation by exploiting the failure to disconnect existing…

  • CVE-2026-41916MedApr 28, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration reload. Newly accepted gateway connections continue using outdated resolved auth state, allowing attackers to bypass authentication…

  • CVE-2026-41356MedApr 23, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously compromised credentials can maintain unauthorized access through existing WebSocket connections after token rotation.

  • CVE-2026-0971MedApr 21, 2026
    risk 0.28cvss 4.3epss 0.00

    An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.

  • CVE-2026-35462MedApr 7, 2026
    risk 0.28cvss 4.3epss 0.00

    Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — regardless of its expiration date — is accepted indefinitely, allowing a…

  • CVE-2026-34362MedMar 27, 2026
    risk 0.28cvss 5.4epss 0.00

    WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a…

  • CVE-2026-30224MedMar 6, 2026
    risk 0.28cvss 5.4epss 0.00

    OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not revoke server-side sessions when a user logs out. Although the browser cookie is cleared, the corresponding session remains valid in server storage until expiry…

  • CVE-2025-68954MedJan 6, 2026
    risk 0.28cvss 5.4epss 0.00

    Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was…

  • CVE-2025-65430MedDec 15, 2025
    risk 0.28cvss 5.4epss 0.00

    An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.

  • CVE-2025-12110MedOct 23, 2025
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the client. The refresh token is accepted and you can continue to request new tokens for the session. As it can lead to a situation where an administrator removes…

  • CVE-2025-11429MedOct 23, 2025
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created while "Remember Me" was active retain their extended session lifetime until they expire, overriding the…

  • CVE-2025-4528MedMay 11, 2025
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mitigates this issue. It is recommended to upgrade…

  • CVE-2024-35160MedNov 23, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7.6 could allow an authenticated user to obtain sensitive information due to insufficient session expiration.