Common Weakness Enumeration

CWE-613

Allowed-with-Review

Insufficient Session Expiration

Abstraction: Base · Status: Incomplete

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

1023 vulnerabilities reference this CWE, most recent first.

GHSA-47V8-26MF-HW38

Vulnerability from github – Published: 2026-09-01 18:30 – Updated: 2026-09-01 18:30
VLAI
Details

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-84203"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-613"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-01T16:17:34Z",
    "severity": "HIGH"
  },
  "details": "Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.",
  "id": "GHSA-47v8-26mf-hw38",
  "modified": "2026-09-01T18:30:44Z",
  "published": "2026-09-01T18:30:44Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84203"
    },
    {
      "type": "WEB",
      "url": "https://github.com/usememos/memos"
    },
    {
      "type": "WEB",
      "url": "https://github.com/usememos/memos/blob/v0.30.0/server/auth/authenticator.go"
    },
    {
      "type": "WEB",
      "url": "https://github.com/usememos/memos/blob/v0.30.0/server/router/api/v1/user_service.go"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/memos-0.26.0-through-0.30.0-insufficient-session-expiration-on-password-change"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-48RG-3G52-267G

Vulnerability from github – Published: 2026-07-14 21:32 – Updated: 2026-07-14 21:32
VLAI
Details

ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-48329"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-613"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-07-14T21:16:59Z",
    "severity": "LOW"
  },
  "details": "ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.",
  "id": "GHSA-48rg-3g52-267g",
  "modified": "2026-07-14T21:32:23Z",
  "published": "2026-07-14T21:32:23Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48329"
    },
    {
      "type": "WEB",
      "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-4957-H36G-34J9

Vulnerability from github – Published: 2026-07-05 09:30 – Updated: 2026-07-05 09:30
VLAI
Details

A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-14725"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-613"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-07-05T08:16:27Z",
    "severity": "LOW"
  },
  "details": "A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used.",
  "id": "GHSA-4957-h36g-34j9",
  "modified": "2026-07-05T09:30:24Z",
  "published": "2026-07-05T09:30:24Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14725"
    },
    {
      "type": "WEB",
      "url": "https://medium.com/@hemantrajbhati5555/improper-session-invalidation-in-online-boat-reservation-system-using-php-acebd53a8ae7"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/cve/CVE-2026-14725"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/submit/847674"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/vuln/376311"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/vuln/376311/cti"
    },
    {
      "type": "WEB",
      "url": "https://www.sourcecodester.com"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-4CX2-827F-FP6C

Vulnerability from github – Published: 2022-05-24 17:33 – Updated: 2022-05-24 17:33
VLAI
Details

Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2020-15950"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-613"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2020-11-05T15:15:00Z",
    "severity": "HIGH"
  },
  "details": "Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.",
  "id": "GHSA-4cx2-827f-fp6c",
  "modified": "2022-05-24T17:33:12Z",
  "published": "2022-05-24T17:33:12Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-15950"
    },
    {
      "type": "WEB",
      "url": "https://labs.bishopfox.com/advisories"
    },
    {
      "type": "WEB",
      "url": "https://labs.bishopfox.com/advisories/immuta-version-2.8.2"
    },
    {
      "type": "WEB",
      "url": "https://www.immuta.com"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}

GHSA-4CX3-3C38-J9VV

Vulnerability from github – Published: 2026-05-07 02:13 – Updated: 2026-05-29 21:45
VLAI
Summary
katalyst-koi: Session cookies can be replayed after user logout
Details

Impact

Admin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue to access admin functionality after logout, until the cookie expired or session secrets were rotated.

This affects applications using Koi admin authentication where an admin session cookie may have been exposed, cached, intercepted, or otherwise retained after logout.

Patches

The issue has been patched by recording admin logout time and rejecting any admin session cookie created before the user’s most recent logout.

Users should upgrade to the patched Koi releases once available.

Workarounds

Katalyst Koi recommends upgrading to the latest available version, or back porting the changes released in 5.6.0/4.20.0

Resources

This is an application of https://guides.rubyonrails.org/v5.2.0/security.html#replay-attacks-for-cookiestore-sessions

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "RubyGems",
        "name": "katalyst-koi"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.20.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "RubyGems",
        "name": "katalyst-koi"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "5.0.0"
            },
            {
              "fixed": "5.6.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-44511"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-613"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-07T02:13:42Z",
    "nvd_published_at": "2026-05-14T17:16:22Z",
    "severity": "HIGH"
  },
  "details": "### Impact\n\nAdmin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue to access admin functionality after logout, until the cookie expired or session secrets were rotated.\n\nThis affects applications using Koi admin authentication where an admin session cookie may have been exposed, cached, intercepted, or otherwise retained after logout.\n\n### Patches\n\nThe issue has been patched by recording admin logout time and rejecting any admin session cookie created before the user\u2019s most recent logout.\n\nUsers should upgrade to the patched Koi releases once available.\n\n### Workarounds\n\nKatalyst Koi recommends upgrading to the latest available version, or back porting the changes released in 5.6.0/4.20.0\n\n### Resources\n\nThis is an application of https://guides.rubyonrails.org/v5.2.0/security.html#replay-attacks-for-cookiestore-sessions",
  "id": "GHSA-4cx3-3c38-j9vv",
  "modified": "2026-05-29T21:45:23Z",
  "published": "2026-05-07T02:13:42Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/katalyst/koi/security/advisories/GHSA-4cx3-3c38-j9vv"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44511"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/katalyst/koi"
    },
    {
      "type": "WEB",
      "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/katalyst-koi/CVE-2026-44511.yml"
    },
    {
      "type": "WEB",
      "url": "https://guides.rubyonrails.org/v5.2.0/security.html#replay-attacks-for-cookiestore-sessions"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "katalyst-koi: Session cookies can be replayed after user logout"
}

GHSA-4G47-3FX3-5Q52

Vulnerability from github – Published: 2022-05-24 17:35 – Updated: 2022-05-24 17:35
VLAI
Details

In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2020-29667"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-613"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2020-12-10T09:15:00Z",
    "severity": "CRITICAL"
  },
  "details": "In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.",
  "id": "GHSA-4g47-3fx3-5q52",
  "modified": "2022-05-24T17:35:58Z",
  "published": "2022-05-24T17:35:58Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-29667"
    },
    {
      "type": "WEB",
      "url": "https://github.com/jet-pentest/CVE-2020-29667"
    },
    {
      "type": "WEB",
      "url": "http://lanatmservice.ru"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}

GHSA-4GQG-M5MW-G8MG

Vulnerability from github – Published: 2022-05-24 16:56 – Updated: 2024-04-04 01:59
VLAI
Details

Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2018-21018"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-613"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2019-09-22T15:15:00Z",
    "severity": "CRITICAL"
  },
  "details": "Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.",
  "id": "GHSA-4gqg-m5mw-g8mg",
  "modified": "2024-04-04T01:59:08Z",
  "published": "2022-05-24T16:56:38Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-21018"
    },
    {
      "type": "WEB",
      "url": "https://github.com/tootsuite/mastodon/pull/9329"
    },
    {
      "type": "WEB",
      "url": "https://github.com/tootsuite/mastodon/pull/9381"
    },
    {
      "type": "WEB",
      "url": "https://github.com/tootsuite/mastodon/releases/tag/v2.6.2"
    },
    {
      "type": "WEB",
      "url": "https://github.com/tootsuite/mastodon/releases/tag/v2.6.3"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-4H3P-63X6-VWG2

Vulnerability from github – Published: 2022-05-24 17:41 – Updated: 2025-02-10 20:57
VLAI
Summary
Magento Insufficient Session Expiration
Details

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Packagist",
        "name": "magento/community-edition"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.4.0"
            },
            {
              "fixed": "2.4.1-p1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Packagist",
        "name": "magento/community-edition"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.3.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Packagist",
        "name": "magento/project-community-edition"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "2.0.2"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2021-21031"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-613"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-10T18:21:01Z",
    "nvd_published_at": "2021-02-11T20:15:00Z",
    "severity": "MODERATE"
  },
  "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.",
  "id": "GHSA-4h3p-63x6-vwg2",
  "modified": "2025-02-10T20:57:37Z",
  "published": "2022-05-24T17:41:57Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21031"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/magento/magento2"
    },
    {
      "type": "WEB",
      "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Magento Insufficient Session Expiration"
}

GHSA-4H9Q-HVW7-G725

Vulnerability from github – Published: 2022-05-17 00:24 – Updated: 2022-05-17 00:24
VLAI
Details

Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2017-1000136"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-613"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2017-11-03T18:29:00Z",
    "severity": "MODERATE"
  },
  "details": "Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.",
  "id": "GHSA-4h9q-hvw7-g725",
  "modified": "2022-05-17T00:24:06Z",
  "published": "2022-05-17T00:24:06Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-1000136"
    },
    {
      "type": "WEB",
      "url": "https://bugs.launchpad.net/mahara/+bug/1363873"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-4HWW-MCVX-H475

Vulnerability from github – Published: 2024-03-28 21:30 – Updated: 2024-03-28 21:30
VLAI
Details

Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-25954"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-613"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-03-28T19:15:47Z",
    "severity": "MODERATE"
  },
  "details": "Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.",
  "id": "GHSA-4hww-mcvx-h475",
  "modified": "2024-03-28T21:30:31Z",
  "published": "2024-03-28T21:30:31Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25954"
    },
    {
      "type": "WEB",
      "url": "https://www.dell.com/support/kbdoc/en-us/000223366/dsa-2024-115-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    }
  ]
}

Mitigation
Implementation

Set sessions/credentials expiration date.

No CAPEC attack patterns related to this CWE.