← Back
CWE-613

568 CVEs • Abstraction: Base

Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

JSON object

Loading...

CVEs (568)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oklok Project
1Oklok
Jun 17, 2026
May 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it prope...Show more
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excessive verification attempts. This allows an attacker to brute force the four-digit verification code in order to bypass email verification and change the password of a victim account.Show less
1Apache
1Nifi Registry
Jun 17, 2026
Apr 28, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permit...Show more
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours after logging out to make API requests to NiFi Registry.Show less
1Netgear
1Genie
Nov 21, 2024
Apr 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs.
2Kiali
Redhat
2Kiali
Openshift Service Mesh
Jun 17, 2026
Apr 27, 2020
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using tha...Show more
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.Show less
1Opcfoundation
1Unified Architecture .net Standard
Jun 17, 2026
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. T...Show more
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to create a denial-of-service condition against the application. Was ZDI-CAN-10295.Show less
1Jetbrains
1Space
Jun 17, 2026
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
1Jetbrains
1Teamcity
Jun 17, 2026
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
1Hpe
6Msa 1040 Firmware
Msa 1050 FirmwareMsa 2040 Firmware+3 more
Jun 17, 2026
Apr 17, 2020
N/A· v4
6.4 MEDIUM· v3
7.1 HIGH· v2
A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage...Show more
A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.Show less
1Ibm
1Security Information Queue
Jun 17, 2026
Apr 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176...Show more
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176207.Show less
1Ibm
1Content Navigator
Jun 17, 2026
Mar 24, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559.
1Sap
1Enable Now
Jun 17, 2026
Mar 10, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.
1Barracuda
1Web Application Firewall
Nov 21, 2024
Feb 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.
1Otrs
1Otrs
Jun 17, 2026
Feb 7, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14...Show more
The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.
1Rapid7
1Appspider
Jun 17, 2026
Jan 22, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijacking attempts easier,...Show more
The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijacking attempts easier, since the user could believe a session was closed when it was not. This issue affects Rapid7 AppSpider version 3.8.213 and prior versions, and is fixed in version 3.8.215.Show less
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Jan 14, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'.
1Mailstore
2Mailstore
Mailstore Server
Jun 17, 2026
Dec 31, 2019
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
An issue was discovered in MailStore Server (and Service Provider Edition) 9.x through 11.x before 11.2.2. When the directory service (for synchronizing and authenticating users) is set to Generic LDAP, an attacker is ab...Show more
An issue was discovered in MailStore Server (and Service Provider Edition) 9.x through 11.x before 11.2.2. When the directory service (for synchronizing and authenticating users) is set to Generic LDAP, an attacker is able to login as an existing user with an arbitrary password on the second login attempt.Show less
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable e...Show more
Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.Show less
1Apple
5Ipados
Iphone OsMac Os X+2 more
Jun 17, 2026
Dec 18, 2019
N/A· v4
8.4 HIGH· v3
4.6 MEDIUM· v2
An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account...Show more
An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..Show less
1Apache
1Nifi
Jun 17, 2026
Nov 19, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits t...Show more
When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours after logging out to make API requests to NiFi.Show less