CWE-613
Insufficient Session Expiration
Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (608)
page 8 of 31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-1543 | Hig | 0.50 | 8.8 | 0.01 | Mar 21, 2023 | Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6. | ||
| CVE-2023-23929 | Hig | 0.50 | 8.8 | 0.01 | Mar 4, 2023 | vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a validity of 24-48 hours. A fix was released in version 3.8.0. | ||
| CVE-2022-2064 | Hig | 0.50 | 8.8 | 0.01 | Jun 13, 2022 | Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+. | ||
| CVE-2021-25970 | Hig | 0.50 | 8.8 | 0.01 | Oct 20, 2021 | Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed. | ||
| CVE-2020-12690 | Hig | 0.50 | 8.8 | 0.02 | May 7, 2020 | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains every role assignment the creator had… | ||
| CVE-2019-12421 | Hig | 0.50 | 8.8 | 0.02 | Nov 19, 2019 | When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours… | ||
| CVE-2026-44383 | Hig | 0.49 | 7.5 | 0.00 | Jul 10, 2026 | Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend. | ||
| CVE-2026-9096 | Hig | 0.49 | 7.5 | 0.00 | May 28, 2026 | Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning… | ||
| CVE-2021-47740 | Hig | 0.49 | 7.5 | 0.00 | Dec 31, 2025 | KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device… | ||
| CVE-2022-50692 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack active user sessions and gain unauthorized… | ||
| CVE-2025-28059 | Hig | 0.49 | 7.5 | 0.01 | Apr 18, 2025 | An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active… | ||
| CVE-2024-39809 | Hig | 0.49 | 7.5 | 0.00 | Aug 14, 2024 | The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | ||
| CVE-2024-25628 | Hig | 0.49 | 7.6 | 0.00 | Feb 16, 2024 | Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the admin area even after being invalidated/deleted. This issue has been addressed in version 2.0-M4-2402. All users are advised to upgrade. There are no known… | ||
| CVE-2023-4320 | Hig | 0.49 | 7.6 | 0.01 | Dec 18, 2023 | An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity. | ||
| CVE-2023-27891 | Hig | 0.49 | 7.5 | 0.01 | Mar 6, 2023 | rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1. | ||
| CVE-2022-3080 | Hig | 0.49 | 7.5 | 0.02 | Sep 21, 2022 | By sending specific queries to the resolver, an attacker can cause named to crash. | ||
| CVE-2022-24341 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user. | ||
| CVE-2021-45885 | Hig | 0.49 | 7.5 | 0.01 | Dec 29, 2021 | An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password. | ||
| CVE-2021-33982 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2021 | An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3.8.0 and earlier, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions. | ||
| CVE-2021-39113 | Hig | 0.49 | 7.5 | 0.02 | Aug 30, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and… |
- risk 0.50cvss 8.8epss 0.01
Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.
- risk 0.50cvss 8.8epss 0.01
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a validity of 24-48 hours. A fix was released in version 3.8.0.
- risk 0.50cvss 8.8epss 0.01
Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.
- risk 0.50cvss 8.8epss 0.01
Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed.
- risk 0.50cvss 8.8epss 0.02
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains every role assignment the creator had…
- risk 0.50cvss 8.8epss 0.02
When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours…
- risk 0.49cvss 7.5epss 0.00
Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.
- risk 0.49cvss 7.5epss 0.00
Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning…
- risk 0.49cvss 7.5epss 0.00
KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device…
- risk 0.49cvss 7.5epss 0.01
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack active user sessions and gain unauthorized…
- risk 0.49cvss 7.5epss 0.01
An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active…
- risk 0.49cvss 7.5epss 0.00
The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- risk 0.49cvss 7.6epss 0.00
Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the admin area even after being invalidated/deleted. This issue has been addressed in version 2.0-M4-2402. All users are advised to upgrade. There are no known…
- risk 0.49cvss 7.6epss 0.01
An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.
- risk 0.49cvss 7.5epss 0.01
rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.
- risk 0.49cvss 7.5epss 0.02
By sending specific queries to the resolver, an attacker can cause named to crash.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.
- risk 0.49cvss 7.5epss 0.01
An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3.8.0 and earlier, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.
- risk 0.49cvss 7.5epss 0.02
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and…