CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

531 vulnerabilities with CWE-613
CVE-2023-51772 HIGH
One Identity Password Manager <5.13.1 - Privilege Escalation
CVSS 8.8
CVE-2023-4320 HIGH
Red Hat Satellite < 6.13 - Insufficient Session Expiration via Personal Access Token Arithmetic Overflow
CVSS 7.6
CVE-2023-49935 HIGH
Slurm 23.02.x-23.02.6 and 23.11.x < 23.11.1 - Unauthenticated Message Integrity Bypass via Token Reuse
CVSS 8.8
CVE-2023-46326 HIGH
ZStack Cloud <3.10.38 - Privilege Escalation
CVSS 8.8
CVE-2023-49091 HIGH
Cosmos-server <0.13.1 - Privilege Escalation
CVSS 8.8
CVE-2023-47628 MEDIUM
DataHub < 0.12.1 - Insufficient Session Expiration via Stateless Session Cookie
CVSS 4.2
CVE-2023-5889 HIGH
pkp/pkp_web_application_library < 3.3.0-16 - Insufficient Session Expiration
CVSS 8.2
CVE-2023-39695 MEDIUM
Elenos ETG150 FM Transmitter 3.12 - Insufficient Session Expiration
CVSS 5.3
CVE-2023-5865 CRITICAL
phpmyfaq < 3.2.2 - Insufficient Session Expiration
CVSS 9.8
CVE-2023-5838 CRITICAL
linkstack < 4.2.9 - Insufficient Session Expiration
CVSS 9.8
CVE-2023-46158 MEDIUM
IBM WebSphere Application Server Liberty <23.0.0.11 - Info Disclosure
CVSS 4.9
CVE-2023-37504 HIGH
HCL Compass 2.0.0-2.0.3 - Insufficient Session Expiration
CVSS 7.1
CVE-2023-45659 LOW
engelsystem < 2023-09-18 - Insufficient Session Expiration
CVSS 3.6
CVE-2023-33303 HIGH
Fortinet FortiEDR 5.0.0-5.0.1 - Insufficient Session Expiration via API Request
CVSS 8.1
CVE-2023-42768 HIGH
F5 BIG-IP 13.1.0-13.1.5 - Insufficient Session Expiration via iControl REST Role Reversion
CVSS 7.2
CVE-2023-40537 HIGH
F5 BIG-IP 13.1.0-14.1.5 - Insufficient Session Expiration
CVSS 8.1
CVE-2023-40732 LOW
QMS Automotive <V12.39 - Session Hijacking
CVSS 3.9
CVE-2023-41041 LOW
Graylog < 5.0.9 - Insufficient Session Expiration in Multi-Node Cluster
CVSS 2.6
CVE-2023-40178 MEDIUM
node-saml < 4.0.5 - Insufficient Session Expiration via LogoutRequest Reuse
CVSS 5.3
CVE-2023-40025 MEDIUM
Argo CD 2.6.0-2.6.13 - Insufficient Session Expiration in Web Terminal
CVSS 4.7
CVE-2023-40174 MEDIUM
fobybus/social-media-skeleton < 1.0.5 - Insufficient Session Expiration
CVSS 6.8
CVE-2023-37570 HIGH
ESDS Emagic Data Center Management Suit < 6.0 - Insufficient Session Expiration
CVSS 7.2
CVE-2023-4190 MEDIUM
admidio < 4.2.11 - Insufficient Session Expiration
CVSS 6.5
CVE-2023-4126 HIGH
answer < 1.1.0 - Insufficient Session Expiration
CVSS 8.8
CVE-2023-4005 CRITICAL
fossbilling/fossbilling <0.5.5 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 531