VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 30 of 31
  • CVE-2024-55603MedDec 19, 2024
    risk 0.00cvss 6.5epss 0.01

    Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still usable even though their lifetime has exceeded. Kanboard implements a cutom session handler (`app/Core/Session/SessionHandler.php`), to store the session data…

  • CVE-2024-52553HigNov 13, 2024
    risk 0.00cvss 8.8epss 0.01

    Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.

  • CVE-2024-25619LowFeb 14, 2024
    risk 0.00cvss 3.1epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the Access Tokens had also been destroyed, this could have posed security risks to users by allowing an application…

  • CVE-2024-22403LowJan 18, 2024
    risk 0.00cvss 3.0epss 0.00

    Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are invalidated after 10…

  • CVE-2023-49091HigNov 29, 2023
    risk 0.00cvss 8.8epss 0.01

    Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Cosmos-server is vulnerable due to to the authorization header used for user login remaining valid and not expiring after log out. This…

  • CVE-2023-5889HigNov 1, 2023
    risk 0.00cvss 8.2epss 0.00

    Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5838CriOct 29, 2023
    risk 0.00cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.

  • CVE-2023-45659LowOct 17, 2023
    risk 0.00cvss 3.6epss 0.00

    Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained access to a users' account, i.e., logged in and obtained a session, an attackers' session is not terminated if the users' account password is reset. This…

  • CVE-2023-40174MedAug 18, 2023
    risk 0.00cvss 6.8epss 0.00

    Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Insufficient session expiration is a web application security vulnerability that occurs when a web application does not properly manage the lifecycle of a…

  • CVE-2023-4005CriJul 31, 2023
    risk 0.00cvss 9.8epss 0.00

    Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.

  • CVE-2023-32318HigMay 26, 2023
    risk 0.00cvss 7.2epss 0.00

    Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After successfully authenticating with any other…

  • CVE-2023-31140MedMay 8, 2023
    risk 0.00cvss 4.8epss 0.01

    OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a user registers and confirms their first two-factor authentication (2FA) device for an account, existing logged in sessions for that user account are not…

  • CVE-2022-37186MedApr 16, 2023
    risk 0.00cvss 5.9epss 0.01

    In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed…

  • CVE-2022-46177MedJan 5, 2023
    risk 0.00cvss 5.7epss 0.01

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, when a user requests for a password reset link email, then changes their primary email, the old reset email is…

  • CVE-2021-25992CriFeb 10, 2022
    risk 0.00cvss 9.8epss 0.02

    In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.

  • CVE-2021-25981CriJan 3, 2022
    risk 0.00cvss 9.8epss 0.02

    In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin…

  • CVE-2021-43791MedDec 2, 2021
    risk 0.00cvss 6.5epss 0.01

    Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected versions expiration dates on the confirmation objects associated with email invitations were not enforced properly in the new account registration flow. A…

  • CVE-2021-25940HigNov 16, 2021
    risk 0.00cvss 8.8epss 0.01

    In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated, allowing a malicious user to still be logged in and perform arbitrary actions within the…

  • CVE-2021-37693MedAug 13, 2021
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting…

  • CVE-2021-31408MedApr 23, 2021
    risk 0.00cvss 6.3epss 0.00

    Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access…