VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 25 of 31
  • CVE-2024-31447MedApr 8, 2024
    risk 0.27cvss 5.3epss 0.01

    Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST /store-api/account/logout`, the cart will be cleared, but the User won't be logged…

  • CVE-2023-47628MedNov 14, 2023
    risk 0.27cvss 4.2epss 0.00

    DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default settings for stateless session which do not set an expiration time for a cookie. Due to this, if a session cookie were ever leaked, it would be valid forever.…

  • CVE-2023-40178MedAug 23, 2023
    risk 0.27cvss 5.3epss 0.00

    Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOnOrAfter. This could impact the user where they would be…

  • CVE-2023-28001MedJul 11, 2023
    risk 0.27cvss 4.1epss 0.01

    An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via reusing the session of a deleted user in the REST API.

  • CVE-2020-4914MedMay 5, 2023
    risk 0.27cvss 4.2epss 0.00

    IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290.

  • CVE-2023-28472MedApr 28, 2023
    risk 0.27cvss 5.3epss 0.01

    Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.

  • CVE-2019-3867MedMar 18, 2021
    risk 0.27cvss 4.1epss 0.00

    A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

  • CVE-2026-53602medJul 9, 2026
    risk 0.26cvss epss

    ## Summary Two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate *issuance* time — only at poll time. ## 1. Blocklist not…

  • CVE-2025-48929MedMay 28, 2025
    risk 0.26cvss 4.0epss 0.00

    The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.

  • CVE-2023-46121MedNov 15, 2023
    risk 0.26cvss 5.0epss 0.00

    yt-dlp is a youtube-dl fork with additional features and fixes. The Generic Extractor in yt-dlp is vulnerable to an attacker setting an arbitrary proxy for a request to an arbitrary url, allowing the attacker to MITM the request made from yt-dlp's HTTP session. This could lead…

  • CVE-2022-38707MedMay 5, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.

  • CVE-2016-0234MedAug 30, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303.

  • CVE-2025-46344MedApr 29, 2025
    risk 0.25cvss epss 0.00

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal…

  • CVE-2023-45718LowFeb 9, 2024
    risk 0.25cvss 3.9epss 0.00

    Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  

  • CVE-2023-40732LowSep 12, 2023
    risk 0.25cvss 3.9epss 0.00

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.

  • CVE-2023-22591LowMar 15, 2023
    risk 0.25cvss 3.9epss 0.00

    IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. IBM X-Force ID: 243710.

  • CVE-2020-13307LowSep 15, 2020
    risk 0.25cvss 3.8epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.

  • CVE-2020-13302LowSep 14, 2020
    risk 0.25cvss 3.8epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.

  • CVE-2025-66803MedJan 20, 2026
    risk 0.24cvss 4.8epss 0.00

    Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when delayed frame responses reapply session cookies after logout. This can be exploited by remote attackers via selective network delays (e.g. delaying requests…

  • CVE-2025-55254LowDec 17, 2025
    risk 0.24cvss 3.7epss 0.00

    Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages.