HCL Nomad is susceptible to an insufficient session expiration vulnerability. Under certain circumstances, an unauthen
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p
All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 d
A vulnerability, which was classified as problematic, was found in SourceCodester Engineers Online Portal 1.0. Affected
`@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.
cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious
An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application
IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7
Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persi
A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected i
A vulnerability was found in Totolink N350RT 9.3.5u.6255. It has been declared as problematic. Affected by this vulnerab
A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functi
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unkn
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as problematic. Affected by t
Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the
Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attack
In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them usin
Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.
In Siren Investigate before 13.2.2, session keys remain active even after logging out.
Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.
Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLo
IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is no
Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and ab
Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login.
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh t
Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.
An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code a
Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as
ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the sessio
An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Mess
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Direct
Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configurat
A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthoriz
An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attack
rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.
An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6
Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextclo
This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing th
When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's rol
Frequently Asked Questions
What is CWE-613?
CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-613?
There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.
How can I protect against CWE-613 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.
Detect CWE-613 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.
Get Started