目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-613 不充分的会话过期机制 类漏洞列表 414

CWE-613 不充分的会话过期机制 类弱点 414 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-613 属于会话管理缺陷,指网站允许攻击者重用过期的会话凭据或会话 ID 进行授权。攻击者通常通过窃取或猜测旧会话令牌,在合法会话结束后继续访问受保护资源,从而绕过身份验证。开发者应确保会话在用户主动注销、超时或敏感操作后及时失效,并实施严格的会话 ID 轮换机制,防止旧令牌被复用,以保障系统安全。

MITRE CWE 官方描述
CWE:CWE-613 Insufficient Session Expiration(会话过期不足) 英文:根据 WASC 的描述,“Insufficient Session Expiration(会话过期不足)是指网站允许攻击者重用旧的会话凭据(session credentials)或会话 ID(session IDs)进行授权。”
常见影响 (1)
Access Control Bypass Protection Mechanism
缓解措施 (1)
Implementation Set sessions/credentials expiration date.
代码示例 (1)
The following snippet was taken from a J2EE web.xml deployment descriptor in which the session-timeout parameter is explicitly defined (the default value depends on the container). In this case the value is set to -1, which means that a session will never expire.
<web-app> [...snipped...] <session-config> <session-timeout>-1</session-timeout> </session-config> </web-app>
Bad · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-86215 Mustafa Aktas College-Management-System 会话机制问题漏洞 — College-Management-System 4.3 Medium 2026-09-06
CVE-2026-55513 Forgekeep nebula-mesh 会话机制问题漏洞 — nebula-mesh 5.4 Medium 2026-09-04
CVE-2026-61608 SolidInvoice 会话机制问题漏洞 — SolidInvoice 6.8 Medium 2026-09-04
CVE-2026-84480 WWBN AVideo 会话机制问题漏洞 — AVideo 9.8 Critical 2026-09-01
CVE-2026-84203 Memos 会话机制问题漏洞 — memos 8.1 High 2026-09-01
CVE-2026-82909 QuantumNous new-api 会话机制问题漏洞 — new-api 4.3 Medium 2026-08-31
CVE-2026-82469 jeremyevans rodauth 会话机制问题漏洞 — rodauth 5.4 Medium 2026-08-29
CVE-2026-81826 flowintel 会话机制问题漏洞 — flowintel 9.1 Critical 2026-08-27
CVE-2025-62342 HCL IntelliOps Event Management 会话机制问题漏洞 — IEM 6.4 Medium 2026-08-27
CVE-2026-73180 Apache Tomcat 会话机制问题漏洞 — Apache Tomcat - - 2026-08-25
CVE-2026-79664 L1nSn0w Ech0 会话机制问题漏洞 — Ech0 7.4 High 2026-08-25
CVE-2026-77130 TYPO3 SYSSY - TYPO3 Monitoring & Security Checks 会话机制问题漏洞 — Extension "SYSSY - TYPO3 Monitoring & Security Checks" 5.3 Medium 2026-08-25
CVE-2026-75554 hexpm 会话机制问题漏洞 — hexpm 2.3 Low 2026-08-24
CVE-2026-14950 Frauscher Sensortechnik FDS102 会话机制问题漏洞 — FDS 102 9.8 Critical 2026-08-20
CVE-2026-65984 frangoteam FUXA 会话机制问题漏洞 — FUXA 7.5 High 2026-08-18
CVE-2026-45791 Dokploy 会话机制问题漏洞 — dokploy 5.9 Medium 2026-08-17
CVE-2026-73611 File Browser 会话机制问题漏洞 — filebrowser 6.8 Medium 2026-08-13
CVE-2026-66376 JFrog artifactory 会话机制问题漏洞 — artifactory 4.2 Medium 2026-08-12
CVE-2026-17600 Sonatype Nexus Repository 会话机制问题漏洞 — Nexus Repository 3 8.7 High 2026-08-07
CVE-2026-48079 open-reception appointment-booking-software 会话机制问题漏洞 — appointment-booking-software 7.4 High 2026-08-06
CVE-2025-12317 WSO2 Enterprise Integrator 会话机制问题漏洞 — WSO2 Enterprise Integrator 5.0 Medium 2026-08-06
CVE-2025-12627 WSO2 Identity Server 会话机制问题漏洞 — WSO2 Identity Server 2.4 Low 2026-08-06
CVE-2024-8995 WSO2 API Manager 会话机制问题漏洞 — WSO2 API Manager 4.9 Medium 2026-08-06
CVE-2026-60053 Apache Answer 会话机制问题漏洞 — Apache Answer - - 2026-08-05
CVE-2026-39924 Flarum framework 会话机制问题漏洞 — Flarum Framework 6.8 Medium 2026-08-05
CVE-2026-71206 go-shiori shiori 会话机制问题漏洞 — shiori 8.2 High 2026-08-05
CVE-2026-14465 Bilin Software and Informatics Consultancy HUMANIST Digital Human Resources 会话机制问题漏洞 — HUMANIST Digital Human Resources 6.5 Medium 2026-08-04
CVE-2024-40683 IBM operations analytics log analysis 会话机制问题漏洞 — Operations Analytics - Log Analysis 6.3 Medium 2026-07-30
CVE-2026-14227 MikroTik RouterOS 会话机制问题漏洞 — RouterOS 4.9 Medium 2026-07-30
CVE-2026-16970 DFIR-IRIS IRIS 会话机制问题漏洞 — iris-web 4.2 Medium 2026-07-30

CWE-613(不充分的会话过期机制) 是常见的弱点类别,本平台收录该类弱点关联的 414 条 CVE 漏洞。