CWE-613
Insufficient Session Expiration
Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (608)
page 4 of 31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36252 | Hig | 0.57 | 8.8 | 0.01 | Jun 26, 2023 | An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function. | ||
| CVE-2023-1788 | Cri | 0.57 | 9.8 | 0.00 | Apr 5, 2023 | Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6. | ||
| CVE-2023-24426 | Hig | 0.57 | 8.8 | 0.01 | Jan 26, 2023 | Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login. | ||
| CVE-2023-23614 | Hig | 0.57 | 8.8 | 0.01 | Jan 26, 2023 | Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Remember me for 7 days" cookie value makes… | ||
| CVE-2022-43844 | Hig | 0.57 | 8.8 | 0.01 | Jan 5, 2023 | IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is not correctly redirected to the platform log out screen when logging out of IBM RPA for Cloud Pak. IBM X-Force ID: 239081. | ||
| CVE-2022-4070 | Cri | 0.57 | 9.8 | 0.01 | Nov 20, 2022 | Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0. | ||
| CVE-2022-3362 | Cri | 0.57 | 9.8 | 0.01 | Nov 14, 2022 | Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0. | ||
| CVE-2022-2713 | Cri | 0.57 | 9.8 | 0.01 | Aug 8, 2022 | Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0. | ||
| CVE-2022-23669 | Hig | 0.57 | 8.8 | 0.01 | May 17, 2022 | A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | ||
| CVE-2022-23063 | Hig | 0.57 | 8.8 | 0.01 | May 3, 2022 | In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed. | ||
| CVE-2022-22113 | Hig | 0.57 | 8.8 | 0.01 | Jan 13, 2022 | In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was… | ||
| CVE-2021-25979 | Cri | 0.57 | 9.8 | 0.01 | Nov 8, 2021 | Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older… | ||
| CVE-2021-25966 | Hig | 0.57 | 8.8 | 0.01 | Oct 10, 2021 | In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to… | ||
| CVE-2021-20378 | Hig | 0.57 | 8.8 | 0.00 | Jul 7, 2021 | IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 195709. | ||
| CVE-2021-3311 | Cri | 0.57 | 9.8 | 0.03 | Feb 5, 2021 | An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only relevant if an old session… | ||
| CVE-2020-15950 | Hig | 0.57 | 8.8 | 0.01 | Nov 5, 2020 | Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout. | ||
| CVE-2020-6292 | Hig | 0.57 | 8.8 | 0.01 | Jul 14, 2020 | Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration. | ||
| CVE-2020-6291 | Hig | 0.57 | 8.8 | 0.01 | Jul 14, 2020 | SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration | ||
| CVE-2020-4253 | Hig | 0.57 | 8.8 | 0.01 | Mar 24, 2020 | IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559. | ||
| CVE-2019-5462 | Hig | 0.57 | 8.8 | 0.03 | Jan 28, 2020 | A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed. |
- risk 0.57cvss 8.8epss 0.01
An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function.
- risk 0.57cvss 9.8epss 0.00
Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.
- risk 0.57cvss 8.8epss 0.01
Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login.
- risk 0.57cvss 8.8epss 0.01
Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Remember me for 7 days" cookie value makes…
- risk 0.57cvss 8.8epss 0.01
IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is not correctly redirected to the platform log out screen when logging out of IBM RPA for Cloud Pak. IBM X-Force ID: 239081.
- risk 0.57cvss 9.8epss 0.01
Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.
- risk 0.57cvss 9.8epss 0.01
Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- risk 0.57cvss 9.8epss 0.01
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
- risk 0.57cvss 8.8epss 0.01
A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
- risk 0.57cvss 8.8epss 0.01
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.
- risk 0.57cvss 8.8epss 0.01
In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was…
- risk 0.57cvss 9.8epss 0.01
Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older…
- risk 0.57cvss 8.8epss 0.01
In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to…
- risk 0.57cvss 8.8epss 0.00
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 195709.
- risk 0.57cvss 9.8epss 0.03
An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only relevant if an old session…
- risk 0.57cvss 8.8epss 0.01
Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
- risk 0.57cvss 8.8epss 0.01
Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.
- risk 0.57cvss 8.8epss 0.01
SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration
- risk 0.57cvss 8.8epss 0.01
IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559.
- risk 0.57cvss 8.8epss 0.03
A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.