VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 4 of 31
  • CVE-2023-36252HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function.

  • CVE-2023-1788CriApr 5, 2023
    risk 0.57cvss 9.8epss 0.00

    Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.

  • CVE-2023-24426HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login.

  • CVE-2023-23614HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Remember me for 7 days" cookie value makes…

  • CVE-2022-43844HigJan 5, 2023
    risk 0.57cvss 8.8epss 0.01

    IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is not correctly redirected to the platform log out screen when logging out of IBM RPA for Cloud Pak. IBM X-Force ID: 239081.

  • CVE-2022-4070CriNov 20, 2022
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.

  • CVE-2022-3362CriNov 14, 2022
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.

  • CVE-2022-2713CriAug 8, 2022
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.

  • CVE-2022-23669HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2022-23063HigMay 3, 2022
    risk 0.57cvss 8.8epss 0.01

    In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

  • CVE-2022-22113HigJan 13, 2022
    risk 0.57cvss 8.8epss 0.01

    In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was…

  • CVE-2021-25979CriNov 8, 2021
    risk 0.57cvss 9.8epss 0.01

    Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older…

  • CVE-2021-25966HigOct 10, 2021
    risk 0.57cvss 8.8epss 0.01

    In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to…

  • CVE-2021-20378HigJul 7, 2021
    risk 0.57cvss 8.8epss 0.00

    IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 195709.

  • CVE-2021-3311CriFeb 5, 2021
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only relevant if an old session…

  • CVE-2020-15950HigNov 5, 2020
    risk 0.57cvss 8.8epss 0.01

    Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.

  • CVE-2020-6292HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.

  • CVE-2020-6291HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration

  • CVE-2020-4253HigMar 24, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559.

  • CVE-2019-5462HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.03

    A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.