CWE-613
Allowed-with-ReviewInsufficient Session Expiration
Abstraction: Base · Status: Incomplete
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
1019 vulnerabilities reference this CWE, most recent first.
GHSA-9R58-7QGH-QJQ2
Vulnerability from github – Published: 2025-04-14 15:31 – Updated: 2025-04-14 15:31IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
{
"affected": [],
"aliases": [
"CVE-2024-49825"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-14T15:15:23Z",
"severity": "MODERATE"
},
"details": "IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.",
"id": "GHSA-9r58-7qgh-qjq2",
"modified": "2025-04-14T15:31:59Z",
"published": "2025-04-14T15:31:59Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49825"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7230848"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-9RFX-MM7M-3CG2
Vulnerability from github – Published: 2022-05-24 19:16 – Updated: 2022-05-24 19:16Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.
{
"affected": [],
"aliases": [
"CVE-2021-37333"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-10-04T14:15:00Z",
"severity": "CRITICAL"
},
"details": "Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.",
"id": "GHSA-9rfx-mm7m-3cg2",
"modified": "2022-05-24T19:16:29Z",
"published": "2022-05-24T19:16:29Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-37333"
},
{
"type": "WEB",
"url": "https://www.navidkagalwalla.com/booking-core-vulnerabilities"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-9RPJ-R444-XVP8
Vulnerability from github – Published: 2023-08-08 09:30 – Updated: 2024-04-04 06:37This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system.
{
"affected": [],
"aliases": [
"CVE-2023-37570"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-08-08T09:15:10Z",
"severity": "HIGH"
},
"details": "This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. \nBy reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system.\n",
"id": "GHSA-9rpj-r444-xvp8",
"modified": "2024-04-04T06:37:47Z",
"published": "2023-08-08T09:30:20Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37570"
},
{
"type": "WEB",
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01\u0026VLCODE=CIVN-2023-0226"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-9V5V-3JHC-PFFJ
Vulnerability from github – Published: 2025-05-11 03:30 – Updated: 2026-07-31 18:32A vulnerability was found in Dígitro NGC Explorer up to 3.44.15 and classified as problematic. This issue affects some unknown processing. The manipulation leads to session expiration. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
{
"affected": [],
"aliases": [
"CVE-2025-4528"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-11T03:15:24Z",
"severity": "MODERATE"
},
"details": "A vulnerability was found in D\u00edgitro NGC Explorer up to 3.44.15 and classified as problematic. This issue affects some unknown processing. The manipulation leads to session expiration. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.",
"id": "GHSA-9v5v-3jhc-pffj",
"modified": "2026-07-31T18:32:09Z",
"published": "2025-05-11T03:30:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4528"
},
{
"type": "WEB",
"url": "https://digitro.com/esclarecimentos-recomendacoes-ctir-gov"
},
{
"type": "WEB",
"url": "https://digitro.com/recomendacao-10-2026-ctir-gov"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.308273"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.308273"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.565309"
},
{
"type": "WEB",
"url": "https://vuldb.com/cve/CVE-2025-4528"
},
{
"type": "WEB",
"url": "https://vuldb.com/submit/565309"
},
{
"type": "WEB",
"url": "https://vuldb.com/vuln/308273"
},
{
"type": "WEB",
"url": "https://vuldb.com/vuln/308273/cti"
},
{
"type": "WEB",
"url": "https://www.gov.br/ctir/pt-br/assuntos/alertas-e-recomendacoes/recomendacoes/2026/recomendacao-10-2026"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-9WWP-Q7WQ-JX35
Vulnerability from github – Published: 2024-04-10 17:15 – Updated: 2024-04-11 14:31Impact
At the end of the request handling, it will encrypt all data in the session with a secret key and attach the ciphertext as a cookie value with the defined cookie name. After that, the session on the server side is destroyed. When an encrypted cookie with matching session name is provided with subsequent requests, it will decrypt the ciphertext to get the data. The plugin then creates a new session with the data in the ciphertext. Thus theoretically the web instance is still accessing the data from a server-side session, but technically that session is generated solely from a user provided cookie (which is assumed to be non-craftable because it is encrypted with a secret key not known to the user).
The issue exists in the session removal process. In the delete function of the code, when the session is deleted, it is marked for deletion. However, if an attacker could gain access to the cookie, they could keep using it forever.
Patches
Fixed in 56d66642ecc633cff0606927601e81cdac361370. Update to v7.3.0.
Workarounds
Include a "last update" field in the session, and treat "old sessions" as expired. Make sure to configure your cookie as "http only".
References
- https://hackerone.com/reports/2374253
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@fastify/secure-session"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.3.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2024-31999"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": true,
"github_reviewed_at": "2024-04-10T17:15:50Z",
"nvd_published_at": "2024-04-10T22:15:07Z",
"severity": "HIGH"
},
"details": "### Impact\n\nAt the end of the request handling, it will encrypt all data in the session with a secret key and attach the ciphertext as a cookie value with the defined cookie name. After that, the session on the server side is destroyed. When an encrypted cookie with matching session name is provided with subsequent requests, it will decrypt the ciphertext to get the data. The plugin then creates a new session with the data in the ciphertext. Thus theoretically the web instance is still accessing the data from a server-side session, but technically that session is generated solely from a user provided cookie (which is assumed to be non-craftable because it is encrypted with a secret key not known to the user).\n\nThe issue exists in the session removal process. In the delete function of the code, when the session is deleted, it is marked for deletion. However, if an attacker could gain access to the cookie, they could keep using it forever.\n\n### Patches\n\nFixed in 56d66642ecc633cff0606927601e81cdac361370.\nUpdate to v7.3.0.\n\n### Workarounds\n\nInclude a \"last update\" field in the session, and treat \"old sessions\" as expired. \nMake sure to configure your cookie as \"http only\".\n\n### References\n\n* https://hackerone.com/reports/2374253\n",
"id": "GHSA-9wwp-q7wq-jx35",
"modified": "2024-04-11T14:31:13Z",
"published": "2024-04-10T17:15:50Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/fastify/fastify-secure-session/security/advisories/GHSA-9wwp-q7wq-jx35"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31999"
},
{
"type": "WEB",
"url": "https://github.com/fastify/fastify-secure-session/commit/56d66642ecc633cff0606927601e81cdac361370"
},
{
"type": "PACKAGE",
"url": "https://github.com/fastify/fastify-secure-session"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "@fastify/secure-session: Reuse of destroyed secure session cookie"
}
GHSA-C2HR-FWVR-RXJM
Vulnerability from github – Published: 2023-11-01 03:30 – Updated: 2023-11-01 03:30Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
{
"affected": [],
"aliases": [
"CVE-2023-5889"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-01T01:15:07Z",
"severity": "MODERATE"
},
"details": "Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.",
"id": "GHSA-c2hr-fwvr-rxjm",
"modified": "2023-11-01T03:30:58Z",
"published": "2023-11-01T03:30:58Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5889"
},
{
"type": "WEB",
"url": "https://github.com/pkp/pkp-lib/commit/32d071ef2090fc336bc17d56a86d1dff90c26f0b"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/fba2991a-1b8a-4c89-9689-d708526928e1"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-C3W2-9VQM-66R7
Vulnerability from github – Published: 2024-01-10 00:30 – Updated: 2024-01-10 00:30A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-250118 is the identifier assigned to this vulnerability.
{
"affected": [],
"aliases": [
"CVE-2024-0350"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-09T23:15:09Z",
"severity": "LOW"
},
"details": "A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-250118 is the identifier assigned to this vulnerability.",
"id": "GHSA-c3w2-9vqm-66r7",
"modified": "2024-01-10T00:30:23Z",
"published": "2024-01-10T00:30:23Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0350"
},
{
"type": "WEB",
"url": "https://mega.nz/file/fckFBASJ#lffaC0xY44ri9Ln-7hrUbUtq2GTiE8roiW8guR7QeVE"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.250118"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.250118"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-C4HJ-8XP2-799F
Vulnerability from github – Published: 2025-10-30 00:31 – Updated: 2025-10-30 00:31On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired
{
"affected": [],
"aliases": [
"CVE-2025-54547"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-10-29T23:16:18Z",
"severity": "MODERATE"
},
"details": "On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired",
"id": "GHSA-c4hj-8xp2-799f",
"modified": "2025-10-30T00:31:02Z",
"published": "2025-10-30T00:31:02Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54547"
},
{
"type": "WEB",
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/22538-security-advisory-0124"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-C5QW-PGMJ-MR6G
Vulnerability from github – Published: 2022-05-13 01:05 – Updated: 2022-05-13 01:05A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections until the device is rebooted. A deleted dynamic VPN connection should be immediately disallowed from establishing new VPN connections. Due to an error in token caching, deleted users are allowed to connect once a previously successful dynamic VPN connection has been established. A reboot is required to clear the cached authentication token. Affected releases are Junos OS on SRX Series: 12.3X48 versions prior to 12.3X48-D75; 15.1X49 versions prior to 15.1X49-D150; 17.3 versions prior to 17.3R3; 17.4 versions prior to 17.4R2; 18.1 versions prior to 18.1R3; 18.2 versions prior to 18.2R2.
{
"affected": [],
"aliases": [
"CVE-2019-0015"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-01-15T21:29:00Z",
"severity": "MODERATE"
},
"details": "A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections until the device is rebooted. A deleted dynamic VPN connection should be immediately disallowed from establishing new VPN connections. Due to an error in token caching, deleted users are allowed to connect once a previously successful dynamic VPN connection has been established. A reboot is required to clear the cached authentication token. Affected releases are Junos OS on SRX Series: 12.3X48 versions prior to 12.3X48-D75; 15.1X49 versions prior to 15.1X49-D150; 17.3 versions prior to 17.3R3; 17.4 versions prior to 17.4R2; 18.1 versions prior to 18.1R3; 18.2 versions prior to 18.2R2.",
"id": "GHSA-c5qw-pgmj-mr6g",
"modified": "2022-05-13T01:05:18Z",
"published": "2022-05-13T01:05:18Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-0015"
},
{
"type": "WEB",
"url": "https://kb.juniper.net/JSA10915"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/106668"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-C673-WFH5-4255
Vulnerability from github – Published: 2022-05-24 17:00 – Updated: 2024-04-04 02:39Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.
{
"affected": [],
"aliases": [
"CVE-2019-11168"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-11-14T17:15:00Z",
"severity": "CRITICAL"
},
"details": "Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.",
"id": "GHSA-c673-wfh5-4255",
"modified": "2024-04-04T02:39:29Z",
"published": "2022-05-24T17:00:57Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-11168"
},
{
"type": "WEB",
"url": "https://support.f5.com/csp/article/K64346530?utm_source=f5support\u0026amp%3Butm_medium=RSS"
},
{
"type": "WEB",
"url": "https://support.f5.com/csp/article/K64346530?utm_source=f5support\u0026amp;utm_medium=RSS"
},
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00313.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"type": "CVSS_V3"
}
]
}
Mitigation
Set sessions/credentials expiration date.
No CAPEC attack patterns related to this CWE.