CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

576 vulnerabilities with CWE-613
CVE-2022-31677 MEDIUM
Pinniped 0.3.0-0.18.9 - Insufficient Session Expiration
CVSS 5.4
CVE-2022-34624 MEDIUM
Mealie 1.0.0beta3 - Insufficient Session Expiration
CVSS 5.9
CVE-2022-2713 CRITICAL
Cockpit < 2.2.0 - Insufficient Session Expiration
CVSS 9.8
CVE-2022-35728 HIGH
BIG-IP <17.0.0.1, 16.1.x <16.1.3.1, 15.1.x <15.1.6.1, 14.1.x <14.1....
CVSS 8.1
CVE-2022-30699 MEDIUM
NLnet Labs Unbound <=1.16.1 - Info Disclosure
CVSS 6.5
CVE-2022-30698 MEDIUM
Unbound <= 1.16.1 - Insufficient Session Expiration via Delegation Cache
CVSS 6.5
CVE-2022-31145 MEDIUM
FlyteAdmin <1.1.30 - Info Disclosure
CVSS 6.5
CVE-2022-33137 HIGH
SIMATIC MV540-560 <V3.3 - Auth Bypass
CVSS 8.0
CVE-2022-2306 HIGH
Old Session Tokens - Info Disclosure
CVSS 7.5
CVE-2022-22318 CRITICAL
IBM Curam Social Program Management <8.0.2 - Privilege Escalation
CVSS 9.8
CVE-2022-22317 CRITICAL
IBM Curam Social Program Mgmt <8.0.1 - Privilege Escalation
CVSS 9.8
CVE-2022-31050 MEDIUM
TYPO3 <9.5.34 ELTS, <10.4.29, <11.5.11 - Info Disclosure
CVSS 6.0
CVE-2022-2064 HIGH
nocodb < 0.91.7 - Insufficient Session Expiration
CVSS 8.8
CVE-2022-30277 MEDIUM
BD Synapsys 4.20, 4.20 SR1, 4.30 - Insufficient Session Expiration
CVSS 5.7
CVE-2022-23669 HIGH
Arubanetworks Clearpass Policy Manager < 6.7.14 - Insufficient Session Expiration
CVSS 8.8
CVE-2022-24042 CRITICAL
Siemens Desigo Pxc5 Firmware < 02.20.142.10-10884 - Insufficient Session Expiration
CVSS 9.1
CVE-2022-23063 HIGH
Shopizer 2.3.0-3.0.1 - Insufficient Session Expiration
CVSS 8.8
CVE-2022-25590 MEDIUM
SurveyKing v0.2.0 - Insufficient Session Expiration
CVSS 6.5
CVE-2022-0991 HIGH
admidio < 4.1.9 - Insufficient Session Expiration
CVSS 7.1
CVE-2022-24743 HIGH
Sylius <1.10.11-1.11.2 - Info Disclosure
CVSS 7.1
CVE-2022-24744 LOW
Shopware < 6.4.8.1 - Insufficient Session Expiration
CVSS 2.6
CVE-2022-24732 MEDIUM
Maddy Mail Server <0.5.4 - Info Disclosure
CVSS 6.3
CVE-2022-24341 HIGH
JetBrains TeamCity <2021.2.1 - Info Disclosure
CVSS 7.5
CVE-2022-24332 MEDIUM
JetBrains TeamCity <2021.2 - Info Disclosure
CVSS 5.3
CVE-2022-22113 HIGH
DayByDay CRM <2.2.1 - Info Disclosure
CVSS 8.8
Details
Vulnerabilities 576