Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-613

MITRE ↗

CWE-613

69
CRITICAL
191
HIGH
263
MEDIUM
47
LOW
596 CVEs · Page 8/12
7.1
CVE-2023-37504

HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions

6.9
CVE-2023-25562

DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on

6.8
CVE-2023-22771

An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation o

6.8
CVE-2023-40174

Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html

6.8
CVE-2022-3916

A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especi

6.7
CVE-2023-28003

A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized

6.5
CVE-2023-0227

Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.

6.5
CVE-2023-37919

Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain

6.5
CVE-2023-4190

Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.

6.3
CVE-2022-24895

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating us

6.3
CVE-2023-0041

IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration

6.2
CVE-2023-2788

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with adm

5.9
CVE-2023-22492

ZITADEL is a combination of Auth0 and Keycloak. RefreshTokens is an OAuth 2.0 feature that allows applications to retrie

5.9
CVE-2022-37186

In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the time

5.7
CVE-2022-46177

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta

5.7
CVE-2021-3844

Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on

5.6
CVE-2022-48317

Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 a

5.5
CVE-2022-22371

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change

5.5
CVE-2022-34392

SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An aut

5.4
CVE-2023-33005

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.

5.3
CVE-2023-40178

Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp

5.3
CVE-2021-20581

IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient s

5.3
CVE-2023-39695

Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter

4.9
CVE-2023-46158

IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to i

4.8
CVE-2023-31140

OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a

4.7
CVE-2023-1854

A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Aff

4.7
CVE-2023-40025

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version

4.3
CVE-2023-20903

This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an e

4.3
CVE-2023-31139

DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.3

4.2
CVE-2020-4914

IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local us

4.2
CVE-2023-47628

DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default s

4.1
CVE-2023-28001

An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute un

4.0
CVE-2022-38707

IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient sess

3.9
CVE-2023-22591

IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access t

3.9
CVE-2023-40732

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected app

3.7
CVE-2023-22732

Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiratio

3.6
CVE-2023-45659

Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained acc

2.6
CVE-2023-41041

Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged

9.8
CVE-2021-25981

In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerab

9.8
CVE-2021-22820

A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized

9.8
CVE-2021-25992

In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It

9.8
CVE-2022-22317

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authen

9.8
CVE-2022-22318

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authen

9.8
CVE-2022-2713

Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.

9.8
CVE-2022-3362

Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.

9.8
CVE-2022-4070

Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.

9.8
CVE-2022-36179

Fusiondirectory 1.3 suffers from Improper Session Handling.

9.1
CVE-2022-24042

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.

9.1
CVE-2022-2782

In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper valid

8.8
CVE-2022-22113

In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a passwor

Frequently Asked Questions

What is CWE-613?

CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-613?

There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.

How can I protect against CWE-613 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.

Detect CWE-613 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.

Get Started