← Back
CWE-613

568 CVEs • Abstraction: Base

Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

JSON object

Loading...

CVEs (568)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Typo3
1Typo3
Jun 17, 2026
Dec 14, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When users reset their password using the corresponding password recovery functionality, existing sessio...Show more
TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When users reset their password using the corresponding password recovery functionality, existing sessions for that particular user account were not revoked. This applied to both frontend user sessions and backend user sessions. This issue is patched in versions 10.4.33, 11.5.20, 12.1.1.Show less
1Ibm
1Datapower Gateway
Jun 17, 2026
Nov 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not invalidate session after a password change which could allow an authen...Show more
IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235527. Show less
1Fusiondirectory
1Fusiondirectory
Jul 9, 2026
Nov 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Fusiondirectory 1.3 suffers from Improper Session Handling.
1Librenms
1Librenms
Jun 17, 2026
Nov 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.
1Ikus Soft
1Rdiffweb
Jun 17, 2026
Nov 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.
1Hashicorp
1Nomad
Jun 17, 2026
Nov 10, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
1Ibm
1Mq Appliance
Jun 17, 2026
Nov 3, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235532."
1Glpi Project
1Glpi
Jun 17, 2026
Nov 3, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Deleted/deactivated user...Show more
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Deleted/deactivated user could continue to use their account as long as its cookie is valid. This issue has been patched, please upgrade to version 10.0.4. There are currently no known workarounds.Show less
1Octopus
1Octopus Server
Jun 17, 2026
Oct 27, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.
1Lannerinc
1Iac Ast2500a Firmware
Jun 17, 2026
Oct 24, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attacks against users. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
1Devhubapp
1Devhub
Jul 9, 2026
Oct 17, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
devhub 0.102.0 was discovered to contain a broken session control.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Oct 7, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699.
1Apache
1Airflow
Jun 17, 2026
Oct 7, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.
1Rapid7
1Insightvm
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the det...Show more
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last webpage visited by previous userShow less
1Octoprint
1Octoprint
Jun 17, 2026
Sep 21, 2022
N/A· v4
4.4 MEDIUM· v3
N/A· v2
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
2Fedoraproject
Isc
2Bind
Fedora
Jun 17, 2026
Sep 21, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
By sending specific queries to the resolver, an attacker can cause named to crash.
1Vmware
1Pinniped
Jun 17, 2026
Aug 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to co...Show more
An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their refresh token might allow.Show less
1Mealie
1Mealie
Jul 9, 2026
Aug 19, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
1Agentejo
1Cockpit
Jun 17, 2026
Aug 8, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
1F5
12Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+9 more
Jun 17, 2026
Aug 4, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated...Show more
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain valid for a limited time after logging out from the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less