VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 26 of 31
  • CVE-2025-57766MedSep 8, 2025
    risk 0.24cvss 4.8epss 0.00

    Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating a vulnerability chaining opportunity where attackers who have obtained session tokens through other attack…

  • CVE-2024-12667LowDec 16, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is…

  • CVE-2024-11208LowNov 14, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather…

  • CVE-2022-45862LowAug 13, 2024
    risk 0.24cvss 3.7epss 0.00

    An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions;…

  • CVE-2024-0944LowJan 26, 2024
    risk 0.24cvss 3.7epss 0.02

    A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. The attack may be launched remotely. The…

  • CVE-2024-0943LowJan 26, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in Totolink N350RT 9.3.5u.6255. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. The attack can be launched remotely. The…

  • CVE-2024-0942LowJan 26, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to launch the attack remotely. The…

  • CVE-2023-40025MedAug 23, 2023
    risk 0.24cvss 4.7epss 0.00

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open web terminal sessions do not expire. This bug allows users to send any websocket messages even if the token has already expired.…

  • CVE-2022-40228LowNov 22, 2022
    risk 0.24cvss 3.7epss 0.00

    IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM…

  • CVE-2021-22136LowMay 13, 2021
    risk 0.23cvss 3.5epss 0.00

    In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions,…

  • CVE-2020-13305LowSep 14, 2020
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upon removing a user from a project.

  • CVE-2020-1776LowJul 20, 2020
    risk 0.23cvss 3.5epss 0.01

    When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not be used to access ticket data in the case the agent is invalid. This issue affects ((OTRS)) Community Edition: 6.0.28 and prior versions. OTRS: 7.0.18 and prior…

  • CVE-2022-2888MedSep 21, 2022
    risk 0.22cvss 4.4epss 0.00

    If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.

  • CVE-2024-29402MedApr 16, 2024
    risk 0.21cvss 4.3epss 0.00

    cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious activity.

  • CVE-2024-31995MedApr 10, 2024
    risk 0.21cvss 4.3epss 0.00

    `@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.1, when invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `expires` property is not properly checked…

  • CVE-2019-5641LowSep 21, 2022
    risk 0.21cvss 3.3epss 0.00

    Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last webpage visited by previous user

  • CVE-2020-6197LowMar 10, 2020
    risk 0.21cvss 3.3epss 0.01

    SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.

  • CVE-2026-56664MedJul 10, 2026
    risk 0.20cvss 4.2epss 0.00

    ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits the iat claim, allowing…

  • CVE-2025-62340LowJun 17, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity

  • CVE-2026-41519MedMay 7, 2026
    risk 0.20cvss 4.2epss 0.00

    Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been…