VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 8 of 31
  • CVE-2023-1543HigMar 21, 2023
    risk 0.50cvss 8.8epss 0.01

    Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.

  • CVE-2023-23929HigMar 4, 2023
    risk 0.50cvss 8.8epss 0.01

    vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a validity of 24-48 hours. A fix was released in version 3.8.0.

  • CVE-2022-2064HigJun 13, 2022
    risk 0.50cvss 8.8epss 0.01

    Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.

  • CVE-2021-25970HigOct 20, 2021
    risk 0.50cvss 8.8epss 0.01

    Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed.

  • CVE-2020-12690HigMay 7, 2020
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains every role assignment the creator had…

  • CVE-2019-12421HigNov 19, 2019
    risk 0.50cvss 8.8epss 0.02

    When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours…

  • CVE-2026-44383HigJul 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.

  • CVE-2026-9096HigMay 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning…

  • CVE-2021-47740HigDec 31, 2025
    risk 0.49cvss 7.5epss 0.00

    KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device…

  • CVE-2022-50692HigDec 30, 2025
    risk 0.49cvss 7.5epss 0.01

    SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack active user sessions and gain unauthorized…

  • CVE-2025-28059HigApr 18, 2025
    risk 0.49cvss 7.5epss 0.01

    An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active…

  • CVE-2024-39809HigAug 14, 2024
    risk 0.49cvss 7.5epss 0.00

    The Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2024-25628HigFeb 16, 2024
    risk 0.49cvss 7.6epss 0.00

    Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the admin area even after being invalidated/deleted. This issue has been addressed in version 2.0-M4-2402. All users are advised to upgrade. There are no known…

  • CVE-2023-4320HigDec 18, 2023
    risk 0.49cvss 7.6epss 0.01

    An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.

  • CVE-2023-27891HigMar 6, 2023
    risk 0.49cvss 7.5epss 0.01

    rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.

  • CVE-2022-3080HigSep 21, 2022
    risk 0.49cvss 7.5epss 0.02

    By sending specific queries to the resolver, an attacker can cause named to crash.

  • CVE-2022-24341HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.

  • CVE-2021-45885HigDec 29, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.

  • CVE-2021-33982HigSep 8, 2021
    risk 0.49cvss 7.5epss 0.01

    An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3.8.0 and earlier, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.

  • CVE-2021-39113HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.02

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and…