Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-613 (不充分的会话过期机制) — Vulnerability Class 414

414 vulnerabilities classified as CWE-613 (不充分的会话过期机制). AI Chinese analysis included.

CWE-613 represents a critical authentication weakness where web applications fail to properly invalidate session identifiers after a user logs out or after a period of inactivity. This flaw allows attackers to exploit stale session tokens, often obtained through network sniffing, session fixation, or simply waiting for a user to abandon a shared device. By reusing these expired credentials, adversaries can bypass authentication mechanisms and gain unauthorized access to sensitive user accounts or administrative functions without needing to crack passwords. To mitigate this risk, developers must implement robust session management protocols that enforce strict expiration policies. This includes setting appropriate timeout durations for both active and idle sessions, ensuring that logout actions immediately invalidate server-side session data, and utilizing secure, HttpOnly cookies to prevent client-side script access to session identifiers.

MITRE CWE Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Common Consequences (1)
Access Control Bypass Protection Mechanism
Mitigations (1)
Implementation Set sessions/credentials expiration date.
Examples (1)
The following snippet was taken from a J2EE web.xml deployment descriptor in which the session-timeout parameter is explicitly defined (the default value depends on the container). In this case the value is set to -1, which means that a session will never expire.
<web-app> [...snipped...] <session-config> <session-timeout>-1</session-timeout> </session-config> </web-app>
Bad · Java
CVE ID Title CVSS Severity Published
CVE-2022-32759 IBM Security Directory Server information disclosure — Security Directory Integrator 5.3 Medium 2024-07-25
CVE-2024-29070 Apache StreamPark: session not invalidated after logout — Apache StreamPark 6.5AI Medium AI 2024-07-23
CVE-2024-41827 JetBrains TeamCity 安全漏洞 — TeamCity 7.4 High 2024-07-22
CVE-2024-27782 Fortinet FortiAIOps 代码问题漏洞 — FortiAIOps 7.7 High 2024-07-09
CVE-2024-5995 Soar Cloud HR Portal - Insufficient Session Expiration — HR Portal 8.8 High 2024-06-14
CVE-2024-35206 Siemens SINEC Traffic Analyzer 代码问题漏洞 — SINEC Traffic Analyzer 7.7 High 2024-06-11
CVE-2024-4680 Insufficient Session Expiration in zenml-io/zenml — zenml-io/zenml 9.1 - 2024-06-08
CVE-2024-35220 @fastify/session reuses destroyed session cookie — session 7.4 High 2024-05-21
CVE-2024-34709 Directus Lacks Session Tokens Invalidation — directus 5.4 Medium 2024-05-13
CVE-2023-40695 IBM Cognos Controller session fixation — Cognos Controller 6.3 Medium 2024-05-03
CVE-2024-22358 IBM UrbanCode Deploy session fixation — UrbanCode Deploy 6.3 Medium 2024-04-12
CVE-2024-31999 @fastify/secure-session: Reuse of destroyed secure session cookie — fastify-secure-session 7.4 High 2024-04-10
CVE-2024-31995 zcap has incomplete expiration checks in capability chains. — zcap 4.3 Medium 2024-04-10
CVE-2024-30262 Contao's remember-me tokens will not be cleared after a password change — contao 5.9 Medium 2024-04-09
CVE-2024-31447 Shopware has Improper Session Handling in store-api — shopware 5.3 Medium 2024-04-08
CVE-2024-25954 Dell PowerScale OneFS 代码问题漏洞 — PowerScale OneFS 5.3 Medium 2024-03-28
CVE-2024-1623 Insufficient session timeout vulnerability in Sagemcom router — FAST3686 V2 Vodafone 7.7 High 2024-03-14
CVE-2023-45600 AiLux imx6 安全漏洞 — imx6 bundle 5.6 Medium 2024-03-05
CVE-2024-21722 [20240201] - Core - Insufficient session expiration in MFA management views — Joomla! CMS 4.3 - 2024-02-20
CVE-2023-50270 Apache DolphinScheduler: Session do not expire after password change — Apache DolphinScheduler 9.1AI Critical AI 2024-02-20
CVE-2024-21492 caddy-security 安全漏洞 — github.com/greenpau/caddy-security 4.8 Medium 2024-02-17
CVE-2024-25628 Insufficient Session Expiration in alf.io — alf.io 7.6 High 2024-02-16
CVE-2024-25619 Destroying OAuth Applications doesn't notify Streaming of Access Tokens being destroyed in mastodon — mastodon 3.1 Low 2024-02-14
CVE-2024-0008 PAN-OS: Insufficient Session Expiration Vulnerability in the Web Interface — PAN-OS 6.6 Medium 2024-02-14
CVE-2024-22389 BIG-IP iControl REST API Vulnerability — BIG-IP 7.2 High 2024-02-14
CVE-2023-45187 IBM Engineering Lifecycle Optimization - Publishing session fixation — Engineering Lifecycle Optimization - Publishing 6.3 Medium 2024-02-09
CVE-2023-50936 IBM PowerSC session fixation — PowerSC 6.3 Medium 2024-02-02
CVE-2024-0944 Totolink T8 cstecgi.cgi session expiration — T8 3.7 Low 2024-01-26
CVE-2024-0943 Totolink N350RT cstecgi.cgi session expiration — N350RT 3.7 Low 2024-01-26
CVE-2024-0942 Totolink N200RE V5 cstecgi.cgi session expiration — N200RE V5 3.7 Low 2024-01-26

Vulnerabilities classified as CWE-613 (不充分的会话过期机制) represent 414 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.