CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

533 vulnerabilities with CWE-613
CVE-2019-5647 MEDIUM
Rapid7 AppSpider < 3.8.213 - Insufficient Session Expiration in Chrome Plugin
CVSS 4.4
CVE-2019-10229 HIGH
MailStore Server 9.x-11.x < 11.2.2 - Insufficient Session Expiration via Generic LDAP Authentication
CVSS 8.8
CVE-2019-11106 MEDIUM
Intel CSME and TXE Firmware - Insufficient Session Expiration
CVSS 6.7
CVE-2019-8803 HIGH
iPadOS < 13.2 - Insufficient Session Expiration
CVSS 8.4
CVE-2019-12421 HIGH
Apache NiFi 1.0.0-1.9.2 - Insufficient Session Expiration via Logout
CVSS 8.8
CVE-2019-8149 CRITICAL
Magento 2.2-2.2.9 and 2.3-2.3.2 - Insecure Session Management
CVSS 9.8
CVE-2019-17375 HIGH
cPanel 81.9999.242-82.0.15 - Insufficient Session Expiration
CVSS 8.8
CVE-2019-9269 HIGH
Android 10 - Local Permissions Bypass via Cached Linux User ID
CVSS 7.3
CVE-2019-5531 MEDIUM
VMware ESXi and vCenter Server - Insufficient Session Expiration
CVSS 5.4
CVE-2019-14826 MEDIUM
FreeIPA >= 4.5.0 - Insufficient Session Expiration
CVSS 4.4
CVE-2019-16133 MEDIUM
Eteams OA <4.0.34 - Info Disclosure
CVSS 6.5
CVE-2019-5638 HIGH
Rapid7 Nexpose <= 6.5.50 - Insufficient Session Expiration
CVSS 8.7
CVE-2019-2386 HIGH
MongoDB Server <4.0.9, <3.6.13, <3.4.22 - Info Disclosure
CVSS 7.1
CVE-2019-7280 HIGH
Prima Systems FlexAir <2.3.38 - Info Disclosure
CVSS 8.8
CVE-2019-6584 HIGH
SIEMENS LOGO!8 - Privilege Escalation
CVSS 8.8
CVE-2019-3790 MEDIUM
Pivotal Ops Manager Authenticated Session Fixation via Refresh Token Bypass
CVSS 6.1
CVE-2019-7215 MEDIUM
Progress Sitefinity 10.1.6536 - Info Disclosure
CVSS 6.5
CVE-2019-4072 MEDIUM
IBM Spectrum Control 5.2.1-5.2.17 - Insufficient Session Expiration
CVSS 6.3
CVE-2019-1003049 HIGH
Jenkins < 2.164.1 and < 2.171 - Insufficient Session Expiration
CVSS 8.1
CVE-2019-0015 MEDIUM
Junos OS on SRX Series Insufficient Session Expiration
CVSS 5.4
CVE-2018-21018 CRITICAL
Mastodon < 2.6.3 - Insufficient Session Expiration
CVSS 9.8
CVE-2018-6634 CRITICAL
Parsec Windows 142-0 and Linux Ubuntu 16.04 LTS Desktop Build 142-1 - Insufficient Session Expiration
CVSS 9.8
CVE-2018-1000814 MEDIUM
aio-libs aiohttp-session <=2.6.0 - Non-Expiring Sessions
CVSS 6.5
CVE-2018-1127 MEDIUM
Red Hat Gluster Storage <3.4.0 - Info Disclosure
CVSS 4.2
CVE-2018-2451 MEDIUM
SAP HANA Extended Application Services - Insufficient Session Expiration
CVSS 6.6
Details
Vulnerabilities 533