HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions
DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on
An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation o
Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especi
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized
Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.
Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating us
IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with adm
ZITADEL is a combination of Auth0 and Keycloak. RefreshTokens is an OAuth 2.0 feature that allows applications to retrie
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the time
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta
Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on
Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 a
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change
SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An aut
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient s
Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter
IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to i
OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a
A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Aff
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version
This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an e
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.3
IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local us
DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default s
An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute un
IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient sess
IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access t
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected app
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiratio
Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained acc
Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged
In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerab
A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized
In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authen
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authen
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.
Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.
Fusiondirectory 1.3 suffers from Improper Session Handling.
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.
In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper valid
In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a passwor
Frequently Asked Questions
What is CWE-613?
CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-613?
There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.
How can I protect against CWE-613 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.
Detect CWE-613 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.
Get Started