← Back
CWE-613

568 CVEs • Abstraction: Base

Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

JSON object

Loading...

CVEs (568)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1I2 Analysts Notebook
Jun 17, 2026
Jul 26, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensitive information from the system. IBM X-Force ID: 196342.
1Ibm
1Guardium Data Encryption
Jun 17, 2026
Jul 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 195709.
1Joomla
1Joomla
Jun 17, 2026
Jul 7, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.
4Debian
EclipseNetapp+1 more
16Active Iq Unified Manager
Autovue For Agile Product Lifecycle ManagementCommunications Element Manager+13 more
Jun 17, 2026
Jun 22, 2021
N/A· v4
3.5 LOW· v3
3.6 LOW· v2
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments w...Show more
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jun 8, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expire...Show more
An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expiredShow less
1Hashicorp
1Vault
Jun 17, 2026
Jun 3, 2021
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as...Show more
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.Show less
1Redhat
1Ansible Tower
Jun 17, 2026
May 27, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that d...Show more
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that does not expire. The original token granted to the user still has access to Ansible Tower, which allows any user that can gain access to the token to be fully authenticated to Ansible Tower. This flaw affects Ansible Tower versions before 3.6.4 and Ansible Tower versions before 3.5.6.Show less
1Elastic
1Kibana
Jun 17, 2026
May 13, 2021
N/A· v4
3.5 LOW· v3
3.6 LOW· v2
In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unint...Show more
In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.Show less
1Cisco
2Adaptive Security Appliance Software
Firepower Threat Defense
Jun 17, 2026
Apr 29, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and relo...Show more
A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition.The vulnerability is due to a crash that occurs during a hash lookup for a SIP pinhole connection. An attacker could exploit this vulnerability by sending crafted SIP traffic through an affected device. A successful exploit could allow the attacker to cause a crash and reload of the affected device.Show less
1Vaadin
2Flow
Vaadin
Jun 17, 2026
Apr 23, 2021
N/A· v4
7.1 HIGH· v3
3.3 LOW· v2
Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Sec...Show more
Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access Fusion endpoints after the user attempted to log out.Show less
1Redhat
1Quay
Jun 17, 2026
Mar 18, 2021
N/A· v4
4.1 MEDIUM· v3
4.4 MEDIUM· v2
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Re...Show more
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.Show less
1Domainmod
1Domainmod
Jun 17, 2026
Mar 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire...Show more
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.Show less
1Mantisbt
1Mantisbt
Nov 21, 2024
Mar 7, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an atta...Show more
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.Show less
3Debian
FedoraprojectSaltstack
3Debian Linux
FedoraSalt
Jun 17, 2026
Feb 27, 2021
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
1Telegram
1Telegram
Jun 17, 2026
Feb 19, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session.
1Magento
1Magento
Jun 17, 2026
Feb 11, 2021
N/A· v4
5.6 MEDIUM· v3
7.5 HIGH· v2
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation of this issue could lead to unauthorized access to restricted resou...Show more
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation of this issue could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.Show less
1Magento
1Magento
Jun 17, 2026
Feb 11, 2021
N/A· v4
5.6 MEDIUM· v3
7.5 HIGH· v2
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized access to restricted resources. Access t...Show more
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.Show less
1Argoproj
1Argo Cd
Jun 17, 2026
Feb 9, 2021
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.
1Ibm
1Security Identity Governance And Intelligence
Jun 17, 2026
Feb 9, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a user to obtain sensitive information from another users' session. IBM X-Force ID: 192912.
1Fortinet
1Fortiisolator
Jun 17, 2026
Feb 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be ab...Show more
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)Show less