VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 9 of 31
  • CVE-2021-35342HigAug 27, 2021
    risk 0.49cvss 7.5epss 0.01

    The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification…

  • CVE-2021-37156HigAug 5, 2021
    risk 0.49cvss 7.5epss 0.01

    Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.

  • CVE-2021-3183HigJan 19, 2021
    risk 0.49cvss 7.5epss 0.01

    Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login profile.

  • CVE-2016-20007HigJan 1, 2021
    risk 0.49cvss 7.5epss 0.01

    The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

  • CVE-2020-24713HigOct 28, 2020
    risk 0.49cvss 7.5epss 0.01

    Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.

  • CVE-2020-15074HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.

  • CVE-2020-10876HigMay 4, 2020
    risk 0.49cvss 7.5epss 0.01

    The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excessive verification attempts. This allows…

  • CVE-2016-11058HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.01

    The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs.

  • CVE-2020-8867HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.03

    This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions.…

  • CVE-2020-11795HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.

  • CVE-2020-11688HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.

  • CVE-2017-12159HigOct 26, 2017
    risk 0.49cvss 7.5epss 0.03

    It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.

  • CVE-2026-48079HigAug 6, 2026
    risk 0.48cvss 7.4epss 0.00

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_token` cookie before calling…

  • CVE-2026-32132HigMar 11, 2026
    risk 0.48cvss 7.4epss 0.00

    ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved code. An improper expiration check of the…

  • CVE-2024-33507HigOct 14, 2025
    risk 0.48cvss 7.4epss 0.00

    An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker…

  • CVE-2024-41827HigJul 22, 2024
    risk 0.48cvss 7.4epss 0.00

    In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration

  • CVE-2021-35034HigDec 29, 2021
    risk 0.48cvss 7.4epss 0.01

    An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

  • CVE-2021-41100HigOct 4, 2021
    risk 0.48cvss 7.4epss 0.01

    Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address change of a user with only the short-lived session token in the `Authorization` header. As the short-lived token is only meant as…

  • CVE-2021-32923HigJun 3, 2021
    risk 0.48cvss 7.4epss 0.01

    HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5,…

  • CVE-2019-19199HigOct 2, 2020
    risk 0.48cvss 7.4epss 0.01

    REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout.