← Back
CWE-613

568 CVEs • Abstraction: Base

Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

JSON object

Loading...

CVEs (568)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pkp
1Pkp Web Application Library
Jun 17, 2026
Nov 1, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
1Elenos
1Etg150 Firmware
Jun 17, 2026
Oct 31, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and data after logging out.
1Phpmyfaq
1Phpmyfaq
Jun 17, 2026
Oct 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
1Linkstack
1Linkstack
Jun 17, 2026
Oct 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.
1Ibm
1Websphere Application Server Liberty
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.
1Hcltech
1Hcl Compass
Jun 17, 2026
Oct 19, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be...Show more
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user. Show less
1Ibm
1Security Verify Privilege On Premises
Jun 17, 2026
Oct 17, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324.
1Engelsystem
1Engelsystem
Jun 17, 2026
Oct 17, 2023
N/A· v4
2.8 LOW· v3
N/A· v2
Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained access to a users' account, i.e., logged in and obtained a session, an attackers' session is not termin...Show more
Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained access to a users' account, i.e., logged in and obtained a session, an attackers' session is not terminated if the users' account password is reset. This vulnerability has been fixed in the commit `dbb089315ff3d`. Users are advised to update their installations. There are no known workarounds for this vulnerability.Show less
1Fortinet
1Fortiedr
Jun 17, 2026
Oct 13, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request
1F5
19Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+16 more
Jun 17, 2026
Oct 10, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP...Show more
When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to iControl REST admin resource.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1F5
18Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+15 more
Jun 17, 2026
Oct 10, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform.  Note: Software versions which have reached End of T...Show more
An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Show less
1Redhat
6Keycloak
Openshift Container PlatformOpenshift Container Platform For Linuxone+3 more
Jun 17, 2026
Sep 20, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session...Show more
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authenticated user; when utilizing the refresh token, they will be issued a token for the original user.Show less
1Siemens
1Qms Automotive
Jun 17, 2026
Sep 12, 2023
N/A· v4
3.9 LOW· v3
N/A· v2
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform se...Show more
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.Show less
1Graylog
1Graylog
Jun 17, 2026
Aug 30, 2023
N/A· v4
3.1 LOW· v3
N/A· v2
Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged out, a user session may still be used for API requests until it has reached its original expiry time...Show more
Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged out, a user session may still be used for API requests until it has reached its original expiry time. Each node maintains an in-memory cache of user sessions. Upon a cache-miss, the session is loaded from the database. After that, the node operates solely on the cached session. Modifications to sessions will update the cached version as well as the session persisted in the database. However, each node maintains their isolated version of the session. When the user logs out, the session is removed from the node-local cache and deleted from the database. The other nodes will however still use the cached session. These nodes will only fail to accept the session id if they intent to update the session in the database. They will then notice that the session is gone. This is true for most API requests originating from user interaction with the Graylog UI because these will lead to an update of the session's "last access" timestamp. If the session update is however prevented by setting the `X-Graylog-No-Session-Extension:true` header in the request, the node will consider the (cached) session valid until the session is expired according to its timeout setting. No session identifiers are leaked. After a user has logged out, the UI shows the login screen again, which gives the user the impression that their session is not valid anymore. However, if the session becomes compromised later, it can still be used to perform API requests against the Graylog cluster. The time frame for this is limited to the configured session lifetime, starting from the time when the user logged out. This issue has been addressed in versions 5.0.9 and 5.1.3. Users are advised to upgrade. Show less
1Node Saml Project
1Node Saml
Jun 17, 2026
Aug 23, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOn...Show more
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOnOrAfter. This could impact the user where they would be logged out from an expired LogoutRequest. In bigger contexts, if LogoutRequests are sent out in mass to different SPs, this could impact many users on a large scale. This issue was patched in version 4.0.5. Show less
1Argoproj
1Argo Cd
Jun 17, 2026
Aug 23, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open web terminal sessions do not expire. This bug allows users to send any w...Show more
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open web terminal sessions do not expire. This bug allows users to send any websocket messages even if the token has already expired. The most straightforward scenario is when a user opens the terminal view and leaves it open for an extended period. This allows the user to view sensitive information even when they should have been logged out already. A patch for this vulnerability has been released in the following Argo CD versions: 2.6.14, 2.7.12 and 2.8.1. Show less
1Fobybus
1Social Media Skeleton
Jun 17, 2026
Aug 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Insufficient session expiration is a web application security vulnerability that occurs when a web...Show more
Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Insufficient session expiration is a web application security vulnerability that occurs when a web application does not properly manage the lifecycle of a user's session. Social media skeleton releases prior to 1.0.5 did not properly limit manage user session lifecycles. This issue has been addressed in version 1.0.5 and users are advised to upgrade. There are no known workarounds for this vulnerability. Show less
1Esds.co
1Emagic Data Center Management
Jun 17, 2026
Aug 8, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system.
1Admidio
1Admidio
Jun 17, 2026
Aug 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.
1Answer
1Answer
Jun 17, 2026
Aug 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.