CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
605 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 2 of 13
- CVE-2019-2386HIGHCVSS 7.1EG 7.12019-08-06
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This iss…
- CVE-2019-3790MEDIUMCVSS 6.1EG 6.12019-06-06
The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authentic…
- CVE-2019-3867MEDIUMCVSS 4.1EG 4.12021-03-18
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 …
- CVE-2019-4072MEDIUMCVSS 6.3EG 6.32019-05-09
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the application back button users can remain …
- CVE-2019-5462HIGHCVSS 8.8EG 8.82020-01-28
A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.
- CVE-2019-5531MEDIUMCVSS 5.4EG 5.42019-09-18
VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an i…
- CVE-2019-5638HIGHCVSS 8.7EG 8.72019-08-21
Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator d…
- CVE-2019-5641MEDIUMCVSS 3.3EG 5.32022-09-21
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in t…
- CVE-2019-5647MEDIUMCVSS 4.4EG 4.42020-01-22
The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijacking attempts easier, since the user coul…
- CVE-2019-6584HIGHCVSS 8.8EG 8.82019-06-12
A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). The integrated webserver does not …
- CVE-2019-7215MEDIUMCVSS 6.5EG 6.52019-06-06
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the…
- CVE-2019-7280HIGHCVSS 8.8EG 8.82019-07-01
Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.
- CVE-2019-8149CRITICALCVSS 9.8EG 9.82019-11-06
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent …
- CVE-2019-8803HIGHCVSS 8.4EG 8.42019-12-18
An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously log…
- CVE-2019-9269HIGHCVSS 7.3EG 7.32019-09-27
In System Settings, there is a possible permissions bypass due to a cached Linux user ID. This could lead to a local permissions bypass with no additional execution privileges needed. User interaction is needed for exploitation. Product: A…
- CVE-2020-0621MEDIUMCVSS 4.4EG 4.42020-01-14
A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'.
- CVE-2020-10709HIGHCVSS 7.1EG 7.12021-05-27
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that does not expire. The…
- CVE-2020-10876HIGHCVSS 7.5EG 7.52020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excess…
- CVE-2020-11688HIGHCVSS 7.5EG 7.52020-04-22
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
- CVE-2020-11795HIGHCVSS 7.5EG 7.52020-04-22
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
- CVE-2020-12690HIGHCVSS 8.8EG 8.82020-05-07
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains…
- CVE-2020-13299HIGHCVSS 8.1EG 8.12020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.
- CVE-2020-13302LOWCVSS 3.8EG 3.82020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.
- CVE-2020-13305LOWCVSS 3.5EG 3.52020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upon removing a user from a project.
- CVE-2020-13307LOWCVSS 3.8EG 3.82020-09-15
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access.
- CVE-2020-13353LOWCVSS 2.5EG 2.52020-11-17
When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.
- CVE-2020-14247MEDIUMCVSS 6.5EG 6.52021-02-04
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.
- CVE-2020-15074HIGHCVSS 7.5EG 7.52020-07-14
OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.
- CVE-2020-15218MEDIUMCVSS 6.8EG 6.82021-01-13
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 …
- CVE-2020-15220MEDIUMCVSS 6.1EG 6.12021-01-13
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions 2.7.2 and 3.0.0.
- CVE-2020-15269HIGHCVSS 7.4EG 7.42020-10-20
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linke…
- CVE-2020-15774MEDIUMCVSS 6.8EG 6.82020-09-18
An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in to Gradle Enterprise and since closed their browser could reopen their browser to access G…
- CVE-2020-15950HIGHCVSS 8.8EG 8.82020-11-05
Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
- CVE-2020-1666MEDIUMCVSS 6.6EG 6.62020-10-16
The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access …
- CVE-2020-1724MEDIUMCVSS 4.3EG 4.32020-05-11
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
- CVE-2020-17473MEDIUMCVSS 5.9EG 5.92020-08-14
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.
- CVE-2020-17474CRITICALCVSS 9.8EG 9.82020-08-14
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.
- CVE-2020-1762HIGHCVSS 7.0EG 7.02020-04-27
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user s…
- CVE-2020-1768MEDIUMCVSS 5.4EG 5.42020-02-07
The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.
- CVE-2020-1776MEDIUMCVSS 3.5EG 4.32020-07-20
When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not be used to access ticket data in the case the agent is invalid. This issue affects ((OTRS)) Community Edition: 6.0.28 an…
- CVE-2020-23136MEDIUMCVSS 5.5EG 5.52020-11-09
Microweber v1.1.18 is affected by no session expiry after log-out.
- CVE-2020-23140HIGHCVSS 8.1EG 8.12020-11-09
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
- CVE-2020-24387HIGHCVSS 7.5EG 7.52020-10-19
An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write op…
- CVE-2020-24713HIGHCVSS 7.5EG 7.52020-10-28
Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
- CVE-2020-25374LOWCVSS 2.6EG 2.62020-10-28
CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.
- CVE-2020-27416CRITICALCVSS 9.8EG 9.82021-12-08
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.
- CVE-2020-27422CRITICALCVSS 9.8EG 9.82020-11-16
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
- CVE-2020-27739CRITICALCVSS 9.8EG 9.82020-10-28
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vul…
- CVE-2020-29012MEDIUMCVSS 5.6EG 5.62021-09-08
An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information about other users configured on the device, should the attack…
- CVE-2020-29667CRITICALCVSS 9.8EG 9.82020-12-10
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →