← Back
CWE-613

568 CVEs • Abstraction: Base

Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

JSON object

Loading...

CVEs (568)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Nlnetlabs
2Fedora
Unbound
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain na...Show more
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.Show less
2Fedoraproject
Nlnetlabs
2Fedora
Unbound
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a r...Show more
NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation information for the subdomain that updates Unbound's delegation cache. This action can be repeated before expiry of the delegation information by querying Unbound for a second level subdomain which the rogue nameserver provides new delegation information. Since Unbound is a child-centric resolver, the ever-updating child delegation information can keep a rogue domain name resolvable long after revocation. From version 1.16.2 on, Unbound checks the validity of parent delegation records before using cached delegation information.Show less
1Flyte
1Flyteadmin
Jun 17, 2026
Jul 13, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. In versions 1.1.30 and prior, authenticated users using an external identity provider can continue to use...Show more
FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. In versions 1.1.30 and prior, authenticated users using an external identity provider can continue to use Access Tokens and ID Tokens even after they expire. Users who use FlyteAdmin as the OAuth2 Authorization Server are unaffected by this issue. A patch is available on the `master` branch of the repository. As a workaround, rotating signing keys immediately will invalidate all open sessions and force all users to attempt to obtain new tokens. Those who use this workaround should continue to rotate keys until FlyteAdmin has been upgraded and hide FlyteAdmin deployment ingress URL from the internet.Show less
1Siemens
6Simatic Mv540 H Firmware
Simatic Mv540 S FirmwareSimatic Mv550 H Firmware+3 more
Jun 17, 2026
Jul 12, 2022
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All vers...Show more
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3). The web session management of affected devices does not invalidate session ids in certain logout scenarios. This could allow an authenticated remote attacker to hijack other users' sessions.Show less
1Heroiclabs
1Nakama
Jun 17, 2026
Jul 5, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Old session tokens can be used to authenticate to the application and send authenticated requests.
1Ibm
1Curam Social Program Management
Jun 17, 2026
Jun 20, 2022
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
1Ibm
1Curam Social Program Management
Jun 17, 2026
Jun 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
1Typo3
1Typo3
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
TYPO3 is an open source web content management system. Prior to versions 9.5.34 ELTS, 10.4.29, and 11.5.11, Admin Tool sessions initiated via the TYPO3 backend user interface had not been revoked even if the correspondin...Show more
TYPO3 is an open source web content management system. Prior to versions 9.5.34 ELTS, 10.4.29, and 11.5.11, Admin Tool sessions initiated via the TYPO3 backend user interface had not been revoked even if the corresponding user account was degraded to lower permissions or disabled completely. This way, sessions in the admin tool theoretically could have been prolonged without any limit. TYPO3 versions 9.5.34 ELTS, 10.4.29, and 11.5.11 contain a fix for the problem.Show less
1Nocodb
1Nocodb
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.
1Bd
1Synapsys
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.7 MEDIUM· v3
3.6 LOW· v2
BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic p...Show more
BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII).Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
May 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Po...Show more
A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.Show less
1Siemens
4Desigo Dxr2 Firmware
Desigo Pxc3 FirmwareDesigo Pxc4 Firmware+1 more
Jun 17, 2026
May 10, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142....Show more
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application returns an AuthToken that does not expire at the defined auto logoff delay timeout. An attacker could be able to capture this token and re-use old session credentials or session IDs for authorization.Show less
1Hcltechsw
1Hcl Commerce
Jun 17, 2026
May 6, 2022
N/A· v4
3.3 LOW· v3
1.9 LOW· v2
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.
1Shopizer
1Shopizer
Jun 17, 2026
May 3, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the...Show more
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.Show less
1Redhat
2Keycloak
Single Sign On
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.1 HIGH· v3
3.3 LOW· v2
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
1Surveyking
1Surveyking
Jul 9, 2026
Mar 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
1Admidio
1Admidio
Jun 17, 2026
Mar 19, 2022
N/A· v4
7.1 HIGH· v3
6.4 MEDIUM· v2
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.
1Sylius
1Sylius
Jun 17, 2026
Mar 14, 2022
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could resu...Show more
Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could result in leak of the existing token and unauthorized password change. The issue is fixed in versions 1.10.11 and 1.11.2. As a workaround, overwrite the `Sylius\Bundle\ApiBundle\CommandHandler\ResetPasswordHandler` class with code provided by the maintainers and register it in a container. More information about this workaround is available in the GitHub Security Advisory.Show less
1Shopware
1Shopware
Jun 17, 2026
Mar 9, 2022
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue...Show more
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6.4.8.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.Show less
1Maddy Project
1Maddy
Jun 17, 2026
Mar 9, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade....Show more
Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired accounts via existing filtering mechanisms.Show less