CWE-613
568 CVEs • Abstraction: Base
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
CVEs (568)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Nlnetlabs2Fedora UnboundJun 17, 2026 Aug 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain na...Show more |
2Fedoraproject Nlnetlabs2Fedora UnboundJun 17, 2026 Aug 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a r...Show more |
FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. In versions 1.1.30 and prior, authenticated users using an external identity provider can continue to use...Show more |
1Siemens 6Simatic Mv540 H Firmware Simatic Mv540 S FirmwareSimatic Mv550 H Firmware+3 moreJun 17, 2026 Jul 12, 2022 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All vers...Show more |
Old session tokens can be used to authenticate to the application and send authenticated requests. |
1Ibm 1Curam Social Program Management Jun 17, 2026 Jun 20, 2022 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. |
1Ibm 1Curam Social Program Management Jun 17, 2026 Jun 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281. |
TYPO3 is an open source web content management system. Prior to versions 9.5.34 ELTS, 10.4.29, and 11.5.11, Admin Tool sessions initiated via the TYPO3 backend user interface had not been revoked even if the correspondin...Show more |
Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+. |
BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic p...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Po...Show more |
1Siemens 4Desigo Dxr2 Firmware Desigo Pxc3 FirmwareDesigo Pxc4 Firmware+1 moreJun 17, 2026 May 10, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142....Show more |
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible. |
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the...Show more |
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name]. |
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application. |
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9. |
Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could resu...Show more |
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue...Show more |
Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade....Show more |