In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed
A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and belo
Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and a
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIM
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the ed
Old session tokens can be used to authenticate to the application and send authenticated requests.
By sending specific queries to the resolver, an attacker can cause named to crash.
Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SA
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the syste
FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. In ve
NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack.
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user
"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an aut
Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement pass
TYPO3 is an open source web content management system. Prior to versions 9.5.34 ELTS, 10.4.29, and 11.5.11, Admin Tool s
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-mi
Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attac
BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited,
IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an authenticated user to
An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticati
devhub 0.102.0 was discovered to contain a broken session control.
TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When
An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x be
In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circums
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can
IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.
Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user sessi
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity
Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health
IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates u
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected v
An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a l
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attack
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, bot
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.or
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable
Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or chang
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows r
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command agai
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an aut
Frequently Asked Questions
What is CWE-613?
CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-613?
There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.
How can I protect against CWE-613 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.
Detect CWE-613 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.
Get Started