CWE-613
Insufficient Session Expiration
Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (608)
page 9 of 31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-35342 | Hig | 0.49 | 7.5 | 0.01 | Aug 27, 2021 | The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification… | ||
| CVE-2021-37156 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2021 | Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated. | ||
| CVE-2021-3183 | Hig | 0.49 | 7.5 | 0.01 | Jan 19, 2021 | Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login profile. | ||
| CVE-2016-20007 | Hig | 0.49 | 7.5 | 0.01 | Jan 1, 2021 | The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy. | ||
| CVE-2020-24713 | Hig | 0.49 | 7.5 | 0.01 | Oct 28, 2020 | Gophish through 0.10.1 does not invalidate the gophish cookie upon logout. | ||
| CVE-2020-15074 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2020 | OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp. | ||
| CVE-2020-10876 | Hig | 0.49 | 7.5 | 0.01 | May 4, 2020 | The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excessive verification attempts. This allows… | ||
| CVE-2016-11058 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2020 | The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs. | ||
| CVE-2020-8867 | Hig | 0.49 | 7.5 | 0.03 | Apr 22, 2020 | This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions.… | ||
| CVE-2020-11795 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains Space through 2020-04-22, the session timeout period was configured improperly. | ||
| CVE-2020-11688 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session. | ||
| CVE-2017-12159 | Hig | 0.49 | 7.5 | 0.03 | Oct 26, 2017 | It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks. | ||
| CVE-2026-48079 | Hig | 0.48 | 7.4 | 0.00 | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_token` cookie before calling… | ||
| CVE-2026-32132 | Hig | 0.48 | 7.4 | 0.00 | Mar 11, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved code. An improper expiration check of the… | ||
| CVE-2024-33507 | Hig | 0.48 | 7.4 | 0.00 | Oct 14, 2025 | An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker… | ||
| CVE-2024-41827 | Hig | 0.48 | 7.4 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration | ||
| CVE-2021-35034 | Hig | 0.48 | 7.4 | 0.01 | Dec 29, 2021 | An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted. | ||
| CVE-2021-41100 | Hig | 0.48 | 7.4 | 0.01 | Oct 4, 2021 | Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address change of a user with only the short-lived session token in the `Authorization` header. As the short-lived token is only meant as… | ||
| CVE-2021-32923 | Hig | 0.48 | 7.4 | 0.01 | Jun 3, 2021 | HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5,… | ||
| CVE-2019-19199 | Hig | 0.48 | 7.4 | 0.01 | Oct 2, 2020 | REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout. |
- risk 0.49cvss 7.5epss 0.01
The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification…
- risk 0.49cvss 7.5epss 0.01
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.
- risk 0.49cvss 7.5epss 0.01
Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login profile.
- risk 0.49cvss 7.5epss 0.01
The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
- risk 0.49cvss 7.5epss 0.01
Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
- risk 0.49cvss 7.5epss 0.01
OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.
- risk 0.49cvss 7.5epss 0.01
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excessive verification attempts. This allows…
- risk 0.49cvss 7.5epss 0.01
The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs.
- risk 0.49cvss 7.5epss 0.03
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions.…
- risk 0.49cvss 7.5epss 0.01
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
- risk 0.49cvss 7.5epss 0.03
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.
- risk 0.48cvss 7.4epss 0.00
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_token` cookie before calling…
- risk 0.48cvss 7.4epss 0.00
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved code. An improper expiration check of the…
- risk 0.48cvss 7.4epss 0.00
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker…
- risk 0.48cvss 7.4epss 0.00
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
- risk 0.48cvss 7.4epss 0.01
An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.
- risk 0.48cvss 7.4epss 0.01
Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address change of a user with only the short-lived session token in the `Authorization` header. As the short-lived token is only meant as…
- risk 0.48cvss 7.4epss 0.01
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5,…
- risk 0.48cvss 7.4epss 0.01
REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout.