VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 24 of 31
  • CVE-2024-32006MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the user session on reboot without logout. This could allow an attacker to bypass Multi-Factor Authentication.

  • CVE-2024-35048MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.

  • CVE-2024-34709MedMay 14, 2024
    risk 0.28cvss 5.4epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens function like the other JWT tokens where they are not actually invalidated when logging out. The `directus_session` gets destroyed and the cookie gets deleted but if…

  • CVE-2024-0260MedJan 7, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file change_password_teacher.php of the component Password Change. The manipulation leads to session expiration. It is possible…

  • CVE-2023-31139MedMay 9, 2023
    risk 0.28cvss 4.3epss 0.01

    DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.37 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.1.2, Personal Access Tokens (PATs) generate unrestricted session cookies. This may lead to a bypass…

  • CVE-2023-20903MedMar 28, 2023
    risk 0.28cvss 4.3epss 0.00

    This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to a client on behalf of a user from that identity provider, the administrator of the…

  • CVE-2022-23502MedDec 14, 2022
    risk 0.28cvss 5.4epss 0.00

    TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When users reset their password using the corresponding password recovery functionality, existing sessions for that particular user account were not revoked. This…

  • CVE-2022-31677MedAug 29, 2022
    risk 0.28cvss 5.4epss 0.00

    An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their…

  • CVE-2021-30943MedAug 24, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue in the handling of group membership was resolved with improved logic. This issue is fixed in iOS 15.2 and iPadOS 15.2, watchOS 8.3, macOS Monterey 12.1. A malicious user may be able to leave a messages group but continue to receive messages in that group.

  • CVE-2020-4696MedNov 30, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session. IBM X-Force ID: 186789.

  • CVE-2017-18905MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.

  • CVE-2020-1724MedMay 11, 2020
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.

  • CVE-2026-66376MedAug 12, 2026
    risk 0.27cvss 4.2epss 0.00

    Credentials for a deleted user may remain valid for a short period under specific conditions.

  • CVE-2026-46401MedJun 5, 2026
    risk 0.27cvss epss 0.00

    HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper session termination vulnerability where authentication tokens remain valid after user logout. This allows attackers who obtain valid tokens to maintain…

  • CVE-2026-41891MedMay 7, 2026
    risk 0.27cvss epss 0.00

    CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0 to before version 0.31.8.0, the auth filter has the deactivated/banned user check commented out. This issue has been…

  • CVE-2026-1163MedApr 8, 2026
    risk 0.27cvss 4.1epss 0.00

    An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This issue arises due to the absence of…

  • CVE-2026-24472MedJan 27, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. The middleware does not respect standard…

  • CVE-2025-1198MedFeb 13, 2025
    risk 0.27cvss 4.2epss 0.00

    An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.

  • CVE-2024-11668MedNov 26, 2024
    risk 0.27cvss 4.2epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results.

  • CVE-2024-48926MedOct 22, 2024
    risk 0.27cvss 4.2epss 0.00

    Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. The Backoffice displays the logout page with a session timeout message…