Fallos del tipo CWE-613

473 resultados

Expiração de Sessão Inadequada

A aplicação não valida ou reforça corretamente o tempo de vida de uma sessão de usuário, permitindo que sessões expiradas ou mal gerenciadas continuem sendo aceitas. Isso abre brecha para roubo de sessão, fixação de sessão ou acesso não autorizado após logout.

Ejemplo

Um usuário faz login em um banco online e recebe um token de sessão. A aplicação não verifica se o token expirou no servidor, então mesmo após 24 horas de inatividade, aquele token continua funcional — um atacante que capturar o token pode acessar a conta indefinidamente.

Cómo mitigar

Implemente timeout rigoroso no servidor (revogue tokens expirados), valide a expiração a cada requisição, use session store confiável (Redis, BD), regenere IDs após login/logout, e considere tokens com TTL curto ou refresh tokens com rotação automática.

CVE-2025-36359HIGHIBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerability.EPSS 0.3%CVE-2026-81826CRITICALFlowintel Fails to Invalidate Active Sessions After Password ChangeEPSS 0.3%CVE-2026-27649MEDIUMCTEK Chargeportal Insufficient Session ExpirationEPSS 0.3%CVE-2022-22371MEDIUMIBM Sterling B2B Integrator Standard Edition session fixationEPSS 0.3%CVE-2025-64386HIGHHIJACKING OF THE TOKEN AND GAINING ACCESSEPSS 0.3%CVE-2024-35206HIGHA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application does not EPSS 0.3%CVE-2025-50485HIGHImproper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to exEPSS 0.3%CVE-2025-31952HIGHHCL iAutomate is affected by an insufficient session expirationEPSS 0.3%CVE-2026-41133HIGHpyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)EPSS 0.3%CVE-2025-50486HIGHImproper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execEPSS 0.3%CVE-2024-11627MEDIUM: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 thrEPSS 0.3%CVE-2026-61452MEDIUMGrav before 2.0.4 Improper Session Invalidation JWT Access TokensEPSS 0.3%CVE-2026-25711MEDIUMChargemap chargemap.com Insufficient Session ExpirationEPSS 0.3%CVE-2026-92616HIGHFileRise < 3.28.0 Privilege Escalation via WebDAV Session InheritanceEPSS 0.3%CVE-2024-23586MEDIUMAn insufficient session timeout vulnerability affects HCL Nomad server on DominoEPSS 0.3%CVE-2026-3401LOWSourceCodester Web-based Pharmacy Product Management System session expirationEPSS 0.3%CVE-2021-31408MEDIUMServer session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19EPSS 0.3%CVE-2025-46336MEDIUMRack session gets restored after deletionEPSS 0.3%CVE-2024-11668MEDIUMInsufficient Session Expiration in GitLabEPSS 0.3%CVE-2025-2185HIGHALBEDO Telecom Net.Time - PTP/NTP Clock Insufficient Session ExpirationEPSS 0.3%