CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

532 vulnerabilities with CWE-613
CVE-2022-39234 MEDIUM
GLPI < 10.0.4 - Insufficient Session Expiration
CVSS 4.7
CVE-2022-2782 CRITICAL
Octopus Server < 2022.2.8351 - Insufficient Session Expiration
CVSS 9.1
CVE-2022-41542 MEDIUM
devhub 0.102.0 - Insufficient Session Expiration
CVSS 5.4
CVE-2022-41291 MEDIUM
IBM InfoSphere Information Server 11.7 - Privilege Escalation
CVSS 6.5
CVE-2022-41672 HIGH
Apache Airflow <2.4.1 - Privilege Escalation
CVSS 8.1
CVE-2022-2888 MEDIUM
OctoPrint < 1.8.3 - Insufficient Session Expiration
CVSS 4.4
CVE-2022-3080 HIGH
BIND >=9.16.14 <9.16.33 - Denial of Service via Specific Queries
CVSS 7.5
CVE-2022-31677 MEDIUM
Pinniped 0.3.0-0.18.9 - Insufficient Session Expiration
CVSS 5.4
CVE-2022-34624 MEDIUM
Mealie 1.0.0beta3 - Insufficient Session Expiration
CVSS 5.9
CVE-2022-2713 CRITICAL
Cockpit < 2.2.0 - Insufficient Session Expiration
CVSS 9.8
CVE-2022-35728 HIGH
BIG-IP <17.0.0.1, 16.1.x <16.1.3.1, 15.1.x <15.1.6.1, 14.1.x <14.1....
CVSS 8.1
CVE-2022-30699 MEDIUM
NLnet Labs Unbound <=1.16.1 - Info Disclosure
CVSS 6.5
CVE-2022-30698 MEDIUM
Unbound <= 1.16.1 - Insufficient Session Expiration via Delegation Cache
CVSS 6.5
CVE-2022-31145 MEDIUM
FlyteAdmin <1.1.30 - Info Disclosure
CVSS 6.5
CVE-2022-33137 HIGH
SIMATIC MV540-560 <V3.3 - Auth Bypass
CVSS 8.0
CVE-2022-2306 HIGH
Old Session Tokens - Info Disclosure
CVSS 7.5
CVE-2022-22318 CRITICAL
IBM Curam Social Program Management <8.0.2 - Privilege Escalation
CVSS 9.8
CVE-2022-22317 CRITICAL
IBM Curam Social Program Mgmt <8.0.1 - Privilege Escalation
CVSS 9.8
CVE-2022-31050 MEDIUM
TYPO3 <9.5.34 ELTS, <10.4.29, <11.5.11 - Info Disclosure
CVSS 6.0
CVE-2022-2064 HIGH
nocodb < 0.91.7 - Insufficient Session Expiration
CVSS 8.8
CVE-2022-30277 MEDIUM
BD Synapsys 4.20, 4.20 SR1, 4.30 - Insufficient Session Expiration
CVSS 5.7
CVE-2022-23669 HIGH
Arubanetworks Clearpass Policy Manager < 6.7.14 - Insufficient Session Expiration
CVSS 8.8
CVE-2022-24042 CRITICAL
Siemens Desigo Pxc5 Firmware < 02.20.142.10-10884 - Insufficient Session Expiration
CVSS 9.1
CVE-2022-23063 HIGH
Shopizer 2.3.0-3.0.1 - Insufficient Session Expiration
CVSS 8.8
CVE-2022-25590 MEDIUM
SurveyKing v0.2.0 - Insufficient Session Expiration
CVSS 6.5
Details
Vulnerabilities 532