CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
576 vulnerabilities with CWE-613
CVE-2024-55603
MEDIUM
Kanboard < 1.2.43 - Insufficient Session Expiration in SessionHandler
CVSS 6.5
CVE-2024-12667
LOW
InvoicePlane < 1.6.1 - Insufficient Session Expiration in /invoices/view
CVSS 3.7
CVE-2024-11668
MEDIUM
GitLab CE/EE <17.4.5-17.6.1 - Auth Bypass
CVSS 4.2
CVE-2024-35160
MEDIUM
IBM Watson Query and Db2 Big SQL on Cloud Pak for Data - Insufficient Session Expiration
CVSS 4.3
CVE-2024-11208
LOW
Apereo CAS 6.6 - Insufficient Session Expiration via Login Service Endpoint
CVSS 3.7
CVE-2024-52553
HIGH
Jenkins OpenId Connect Authentication Plugin < 4.421.v5422614eb_e0a - Insufficient Session Expiration
CVSS 8.8
CVE-2024-46892
MEDIUM
SINEC INS < V1.0 SP2 Update 3 - Insufficient Session Expiration
CVSS 4.9
CVE-2024-52311
MEDIUM
data.all 1.0.0-2.6.0 - Insufficient Session Expiration via Cognito Authentication Tokens
CVSS 6.3
CVE-2024-48926
MEDIUM
Umbraco CMS 8.0-8.18.14, 10.0-10.8.6, 13.0.0-13.5.1 - Insufficient Session Expiration
CVSS 4.2
CVE-2024-45462
MEDIUM
Apache CloudStack <4.18.2.3 & <4.19.1.1 - Info Disclosure
CVSS 6.3
CVE-2024-48827
HIGH
sbondCo Watcharr 1.43.0 - Remote Code Execution and Privilege Escalation via Change Password Function
CVSS 8.8
CVE-2024-46040
MEDIUM
IoT Haat Smart Plug IH-IN-16A-S v5.16.1 - Info Disclosure
CVSS 6.5
CVE-2024-43685
CRITICAL
Microchip TimeProvider 4100 Firmware 1.0-2.4.6 - Session Hijacking via Insufficient Session Expiration
CVSS 9.8
CVE-2024-23586
MEDIUM
HCL Nomad < 1.0.13 - Unauthenticated Insufficient Session Expiration
CVSS 5.3
CVE-2024-8888
CRITICAL
CIRCUTOR Q-SMT Firmware 1.0.4 - Insufficient Session Expiration
CVSS 10.0
CVE-2024-38315
MEDIUM
IBM Aspera Shares <1.11 - Privilege Escalation
CVSS 6.3
CVE-2024-32006
MEDIUM
SINEMA Remote Connect Client <V3.2 SP2 - Auth Bypass
CVSS 4.3
CVE-2024-45187
HIGH
Mage AI - Unauthenticated Remote Code Execution via Deleted User Privilege Escalation
CVSS 7.1
CVE-2024-7998
LOW
Octopus Server 2022.4.8332-2024.1.12931 - Insufficient Session Expiration in OIDC Cookies
CVSS 2.6
CVE-2024-39809
HIGH
F5 BIG-IP Next Central Manager - Insufficient Session Expiration
CVSS 7.5
CVE-2024-42447
CRITICAL
Apache Airflow Providers FAB - Info Disclosure
CVSS 9.8
CVE-2024-29070
CRITICAL
Apache StreamPark 1.0.0-2.1.3 - Insufficient Session Expiration
CVSS 9.1
CVE-2024-41827
HIGH
JetBrains TeamCity < 2024.07 - Insufficient Session Expiration
CVSS 7.4
CVE-2024-27782
HIGH
Fortinet FortiAIOps <2.0.0 - Info Disclosure
CVSS 8.1
CVE-2024-36041
HIGH
KSmserver <5.27.11.1-6.0.5.1 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
576