VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 27 of 31
  • CVE-2026-3401LowMar 2, 2026
    risk 0.20cvss 3.1epss 0.00

    A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of an attack is rather high. It is…

  • CVE-2026-1190LowJan 26, 2026
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the…

  • CVE-2025-46336MedMay 8, 2025
    risk 0.20cvss 4.2epss 0.00

    Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the…

  • CVE-2025-32441MedMay 7, 2025
    risk 0.20cvss 4.2epss 0.00

    Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares…

  • CVE-2024-0350LowJan 9, 2024
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is…

  • CVE-2026-55513medJul 14, 2026
    risk 0.19cvss epss

    ### Summary The `nebula-mgmt` Web UI host-creation path ignores both the server-wide `enrollment_token_ttl` security setting and per-network `network_config.enrollment_token_ttl` overrides. API host creation and token-regeneration paths use the configured TTL resolver, but `POST…

  • CVE-2021-34428LowJun 22, 2021
    risk 0.19cvss 2.9epss 0.01

    For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can…

  • CVE-2026-1272LowApr 23, 2026
    risk 0.18cvss 2.7epss 0.00

    IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.

  • CVE-2021-29846LowJan 26, 2022
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 205256.

  • CVE-2022-22283LowJan 10, 2022
    risk 0.18cvss 2.8epss 0.00

    Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.

  • CVE-2024-41985LowAug 12, 2025
    risk 0.17cvss 2.6epss 0.00

    A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not expire the session without logout. This…

  • CVE-2024-7998LowAug 21, 2024
    risk 0.17cvss 2.6epss 0.00

    In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan.

  • CVE-2023-22732LowJan 17, 2023
    risk 0.17cvss 3.7epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In version 6.4.18.1 an automatic logout into…

  • CVE-2020-25374LowOct 28, 2020
    risk 0.17cvss 2.6epss 0.01

    CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.

  • CVE-2025-12627LowAug 6, 2026
    risk 0.16cvss 2.4epss 0.00

    The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens,…

  • CVE-2026-34454LowApr 14, 2026
    risk 0.16cvss 3.5epss 0.00

    OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In deployments that rely on the sign-in page as part of their logout…

  • CVE-2025-52661LowJan 19, 2026
    risk 0.16cvss 2.4epss 0.00

    HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.

  • CVE-2022-21652LowJan 5, 2022
    risk 0.16cvss 3.5epss 0.01

    Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a…

  • CVE-2021-41247LowNov 4, 2021
    risk 0.16cvss 3.5epss 0.01

    JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not…

  • CVE-2020-13353LowNov 17, 2020
    risk 0.16cvss 2.5epss 0.00

    When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.