Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-613'

View all threats tagged with 'cwe-613'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-613

Threats Tagged 'cwe-613'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-17600: CWE-613 Insufficient Session Expiration in Sonatype Nexus Repository 3CVE-2026-17600
0

Sonatype Nexus Repository 3 contains a vulnerability where active user sessions are not immediately terminated or permissions revoked when the user's account is deleted, deactivated, or password changed. This allows users with existing sessions to continue accessing the repository with their previous permissions until the session expires. The issue could lead to unauthorized access to read, modify, or delete repository content after access should have been revoked.

Join the discussion
CVE-2026-17600: CWE-613 Insufficient Session Expiration in Sonatype Nexus Repository 3CVE-2026-17600
0

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing session to interact with the repository as though the account were still active, until that session independently expired. Depending on the permissions previously held, this could allow continued unauthorized access to read, modify, or delete repository content after access was intended to be revoked.

Join the discussion
CVE-2026-48079: CWE-613: Insufficient Session Expiration in open-reception appointment-booking-softwareCVE-2026-48079
0

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_token` cookie before calling `/api/auth/logout` via an internal `event.fetch()`. The internal fetch consequently runs without the auth cookie, so `apiAuthHandle` rejects it, the logout handler never executes, and `SessionService.revokeSession()` is never called for the current session. The DB session row remains valid until its natural expiry (one week by default). The user sees a successful logout (cookie gone, UI returns to login), but any party still holding a copy of the now-deleted access token can continue making authenticated API calls until the session naturally expires. The root cause is a simple ordering mistake. The same auth subsystem implements the correct order in `/api/auth/logout`: revoke the current DB session first, then delete the cookie. The page-level wrapper does the opposite. Version 1.0.2 initiates server-side logout before removing authentication cookies and first appears in version 1.0.2. Version 2.0.0 later replaces this with a race-free client-side logout flow.

Join the discussion
CVE-2025-12317: CWE-613: Insufficient Session Expiration in WSO2 WSO2 Enterprise IntegratorCVE-2025-12317
0

When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.

Join the discussion
CVE-2025-12627: CWE-613: Insufficient Session Expiration in WSO2 WSO2 Identity ServerCVE-2025-12627
0

The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens, extending their ability to act as the legitimate user. An attacker who gains access to an impersonated user's access token can exploit this weakness to renew their authorization. This results in the continued ability to perform actions on behalf of the actual user, compromising log integrity and traceability by masking the true actor.

Join the discussion
CVE-2024-8995: CWE-613: Insufficient Session Expiration in WSO2 WSO2 API ManagerCVE-2024-8995
0

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code.

Join the discussion
CVE-2026-60053: CWE-613 Insufficient Session Expiration in Apache Software Foundation Apache AnswerCVE-2026-60053
0

Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Join the discussion
CVE-2026-71206: CWE-613 Insufficient Session Expiration in go-shiori shioriCVE-2026-71206
0

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase. Deleting an account or demoting it from owner to a regular role has no effect on tokens already issued to that account — a deleted or demoted owner's token continues authenticating with its original owner-level privileges until natural expiry, which can be up to 30 days with 'remember me' enabled.

Join the discussion
CVE-2026-14465: CWE-613 Insufficient session expiration in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ResourcesCVE-2026-14465
0

Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

Join the discussion
CVE-2026-51953: n/aCVE-2026-51953
0

CVE-2026-51953 is a high severity vulnerability in FeehiCMS version 2.1.1 that allows an attacker to escalate privileges by exploiting flaws in the session management module, authentication logic, and logout handler components. The vulnerability has a CVSS score of 7.4, indicating significant impact on confidentiality and integrity without affecting availability. No official patch or remediation guidance is currently available, and no known exploits are reported in the wild.

Join the discussion

Showing 1 to 10 of 22 results

Filters:Tag: cwe-613
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses