Vulnerabilities > Insufficient Session Expiration

DATE CVE VULNERABILITY TITLE RISK
2022-10-17 CVE-2022-41542 Insufficient Session Expiration vulnerability in Devhubapp Devhub 0.102.0
devhub 0.102.0 was discovered to contain a broken session control.
network
low complexity
devhubapp CWE-613
5.4
2022-10-07 CVE-2022-41291 Insufficient Session Expiration vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
network
low complexity
ibm CWE-613
6.5
2022-10-07 CVE-2022-41672 Insufficient Session Expiration vulnerability in Apache Airflow
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.
network
low complexity
apache CWE-613
8.1
2022-09-21 CVE-2019-5641 Insufficient Session Expiration vulnerability in Rapid7 Insightvm
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last webpage visited by previous user
network
low complexity
rapid7 CWE-613
5.3
2022-09-21 CVE-2022-2888 Insufficient Session Expiration vulnerability in Octoprint
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
local
low complexity
octoprint CWE-613
4.4
2022-08-29 CVE-2022-31677 Insufficient Session Expiration vulnerability in VMWare Pinniped
An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0).
network
low complexity
vmware CWE-613
5.4
2022-08-19 CVE-2022-34624 Insufficient Session Expiration vulnerability in Mealie 0.5.5/1.0.0
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
network
high complexity
mealie CWE-613
5.9
2022-08-08 CVE-2022-2713 Insufficient Session Expiration vulnerability in Agentejo Cockpit
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
network
low complexity
agentejo CWE-613
critical
9.8
2022-08-04 CVE-2022-35728 Insufficient Session Expiration vulnerability in F5 products
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain valid for a limited time after logging out from the Configuration utility.
network
low complexity
f5 CWE-613
critical
9.8
2022-08-01 CVE-2022-30698 Insufficient Session Expiration vulnerability in multiple products
NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack.
network
low complexity
nlnetlabs fedoraproject CWE-613
6.5