A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.
Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure w
IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated u
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In vers
IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticate
Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows
authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions,
A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred.
The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking
wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in
An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all vers
Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to sys
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windo
A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on
A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tok
Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)
On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) mult
CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a loca
IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM De
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which ma
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve
haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a us
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides d
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6,
A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a
A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a mani
An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 pr
Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, s
Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when usi
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token
Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.032
Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.2
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor c
This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API end
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are delet
Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking. This v
The affected products contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker wh
Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unex
Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated,
The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of
OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not exp
Frequently Asked Questions
What is CWE-613?
CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-613?
There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.
How can I protect against CWE-613 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.
Detect CWE-613 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.
Get Started