CWE-613
Allowed-with-ReviewInsufficient Session Expiration
Abstraction: Base · Status: Incomplete
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
1023 vulnerabilities reference this CWE, most recent first.
GHSA-47V8-26MF-HW38
Vulnerability from github – Published: 2026-09-01 18:30 – Updated: 2026-09-01 18:30Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.
{
"affected": [],
"aliases": [
"CVE-2026-84203"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-01T16:17:34Z",
"severity": "HIGH"
},
"details": "Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.",
"id": "GHSA-47v8-26mf-hw38",
"modified": "2026-09-01T18:30:44Z",
"published": "2026-09-01T18:30:44Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84203"
},
{
"type": "WEB",
"url": "https://github.com/usememos/memos"
},
{
"type": "WEB",
"url": "https://github.com/usememos/memos/blob/v0.30.0/server/auth/authenticator.go"
},
{
"type": "WEB",
"url": "https://github.com/usememos/memos/blob/v0.30.0/server/router/api/v1/user_service.go"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/memos-0.26.0-through-0.30.0-insufficient-session-expiration-on-password-change"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-48RG-3G52-267G
Vulnerability from github – Published: 2026-07-14 21:32 – Updated: 2026-07-14 21:32ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
{
"affected": [],
"aliases": [
"CVE-2026-48329"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-14T21:16:59Z",
"severity": "LOW"
},
"details": "ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.",
"id": "GHSA-48rg-3g52-267g",
"modified": "2026-07-14T21:32:23Z",
"published": "2026-07-14T21:32:23Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48329"
},
{
"type": "WEB",
"url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-4957-H36G-34J9
Vulnerability from github – Published: 2026-07-05 09:30 – Updated: 2026-07-05 09:30A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
{
"affected": [],
"aliases": [
"CVE-2026-14725"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-05T08:16:27Z",
"severity": "LOW"
},
"details": "A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used.",
"id": "GHSA-4957-h36g-34j9",
"modified": "2026-07-05T09:30:24Z",
"published": "2026-07-05T09:30:24Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14725"
},
{
"type": "WEB",
"url": "https://medium.com/@hemantrajbhati5555/improper-session-invalidation-in-online-boat-reservation-system-using-php-acebd53a8ae7"
},
{
"type": "WEB",
"url": "https://vuldb.com/cve/CVE-2026-14725"
},
{
"type": "WEB",
"url": "https://vuldb.com/submit/847674"
},
{
"type": "WEB",
"url": "https://vuldb.com/vuln/376311"
},
{
"type": "WEB",
"url": "https://vuldb.com/vuln/376311/cti"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-4CX2-827F-FP6C
Vulnerability from github – Published: 2022-05-24 17:33 – Updated: 2022-05-24 17:33Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
{
"affected": [],
"aliases": [
"CVE-2020-15950"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2020-11-05T15:15:00Z",
"severity": "HIGH"
},
"details": "Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.",
"id": "GHSA-4cx2-827f-fp6c",
"modified": "2022-05-24T17:33:12Z",
"published": "2022-05-24T17:33:12Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-15950"
},
{
"type": "WEB",
"url": "https://labs.bishopfox.com/advisories"
},
{
"type": "WEB",
"url": "https://labs.bishopfox.com/advisories/immuta-version-2.8.2"
},
{
"type": "WEB",
"url": "https://www.immuta.com"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-4CX3-3C38-J9VV
Vulnerability from github – Published: 2026-05-07 02:13 – Updated: 2026-05-29 21:45Impact
Admin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue to access admin functionality after logout, until the cookie expired or session secrets were rotated.
This affects applications using Koi admin authentication where an admin session cookie may have been exposed, cached, intercepted, or otherwise retained after logout.
Patches
The issue has been patched by recording admin logout time and rejecting any admin session cookie created before the user’s most recent logout.
Users should upgrade to the patched Koi releases once available.
Workarounds
Katalyst Koi recommends upgrading to the latest available version, or back porting the changes released in 5.6.0/4.20.0
Resources
This is an application of https://guides.rubyonrails.org/v5.2.0/security.html#replay-attacks-for-cookiestore-sessions
{
"affected": [
{
"package": {
"ecosystem": "RubyGems",
"name": "katalyst-koi"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.20.0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "RubyGems",
"name": "katalyst-koi"
},
"ranges": [
{
"events": [
{
"introduced": "5.0.0"
},
{
"fixed": "5.6.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-44511"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-07T02:13:42Z",
"nvd_published_at": "2026-05-14T17:16:22Z",
"severity": "HIGH"
},
"details": "### Impact\n\nAdmin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue to access admin functionality after logout, until the cookie expired or session secrets were rotated.\n\nThis affects applications using Koi admin authentication where an admin session cookie may have been exposed, cached, intercepted, or otherwise retained after logout.\n\n### Patches\n\nThe issue has been patched by recording admin logout time and rejecting any admin session cookie created before the user\u2019s most recent logout.\n\nUsers should upgrade to the patched Koi releases once available.\n\n### Workarounds\n\nKatalyst Koi recommends upgrading to the latest available version, or back porting the changes released in 5.6.0/4.20.0\n\n### Resources\n\nThis is an application of https://guides.rubyonrails.org/v5.2.0/security.html#replay-attacks-for-cookiestore-sessions",
"id": "GHSA-4cx3-3c38-j9vv",
"modified": "2026-05-29T21:45:23Z",
"published": "2026-05-07T02:13:42Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/katalyst/koi/security/advisories/GHSA-4cx3-3c38-j9vv"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44511"
},
{
"type": "PACKAGE",
"url": "https://github.com/katalyst/koi"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/katalyst-koi/CVE-2026-44511.yml"
},
{
"type": "WEB",
"url": "https://guides.rubyonrails.org/v5.2.0/security.html#replay-attacks-for-cookiestore-sessions"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "katalyst-koi: Session cookies can be replayed after user logout"
}
GHSA-4G47-3FX3-5Q52
Vulnerability from github – Published: 2022-05-24 17:35 – Updated: 2022-05-24 17:35In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
{
"affected": [],
"aliases": [
"CVE-2020-29667"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2020-12-10T09:15:00Z",
"severity": "CRITICAL"
},
"details": "In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.",
"id": "GHSA-4g47-3fx3-5q52",
"modified": "2022-05-24T17:35:58Z",
"published": "2022-05-24T17:35:58Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-29667"
},
{
"type": "WEB",
"url": "https://github.com/jet-pentest/CVE-2020-29667"
},
{
"type": "WEB",
"url": "http://lanatmservice.ru"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-4GQG-M5MW-G8MG
Vulnerability from github – Published: 2022-05-24 16:56 – Updated: 2024-04-04 01:59Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
{
"affected": [],
"aliases": [
"CVE-2018-21018"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-09-22T15:15:00Z",
"severity": "CRITICAL"
},
"details": "Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.",
"id": "GHSA-4gqg-m5mw-g8mg",
"modified": "2024-04-04T01:59:08Z",
"published": "2022-05-24T16:56:38Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-21018"
},
{
"type": "WEB",
"url": "https://github.com/tootsuite/mastodon/pull/9329"
},
{
"type": "WEB",
"url": "https://github.com/tootsuite/mastodon/pull/9381"
},
{
"type": "WEB",
"url": "https://github.com/tootsuite/mastodon/releases/tag/v2.6.2"
},
{
"type": "WEB",
"url": "https://github.com/tootsuite/mastodon/releases/tag/v2.6.3"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-4H3P-63X6-VWG2
Vulnerability from github – Published: 2022-05-24 17:41 – Updated: 2025-02-10 20:57Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.
{
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "magento/community-edition"
},
"ranges": [
{
"events": [
{
"introduced": "2.4.0"
},
{
"fixed": "2.4.1-p1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/community-edition"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.3.6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/project-community-edition"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0.2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2021-21031"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": true,
"github_reviewed_at": "2024-01-10T18:21:01Z",
"nvd_published_at": "2021-02-11T20:15:00Z",
"severity": "MODERATE"
},
"details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.",
"id": "GHSA-4h3p-63x6-vwg2",
"modified": "2025-02-10T20:57:37Z",
"published": "2022-05-24T17:41:57Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21031"
},
{
"type": "PACKAGE",
"url": "https://github.com/magento/magento2"
},
{
"type": "WEB",
"url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
}
],
"summary": "Magento Insufficient Session Expiration"
}
GHSA-4H9Q-HVW7-G725
Vulnerability from github – Published: 2022-05-17 00:24 – Updated: 2022-05-17 00:24Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.
{
"affected": [],
"aliases": [
"CVE-2017-1000136"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-11-03T18:29:00Z",
"severity": "MODERATE"
},
"details": "Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.",
"id": "GHSA-4h9q-hvw7-g725",
"modified": "2022-05-17T00:24:06Z",
"published": "2022-05-17T00:24:06Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-1000136"
},
{
"type": "WEB",
"url": "https://bugs.launchpad.net/mahara/+bug/1363873"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-4HWW-MCVX-H475
Vulnerability from github – Published: 2024-03-28 21:30 – Updated: 2024-03-28 21:30Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
{
"affected": [],
"aliases": [
"CVE-2024-25954"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T19:15:47Z",
"severity": "MODERATE"
},
"details": "Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.",
"id": "GHSA-4hww-mcvx-h475",
"modified": "2024-03-28T21:30:31Z",
"published": "2024-03-28T21:30:31Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25954"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000223366/dsa-2024-115-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"type": "CVSS_V3"
}
]
}
Mitigation
Set sessions/credentials expiration date.
No CAPEC attack patterns related to this CWE.