Fallos del tipo CWE-613

474 resultados

Expiração de Sessão Inadequada

A aplicação não valida ou reforça corretamente o tempo de vida de uma sessão de usuário, permitindo que sessões expiradas ou mal gerenciadas continuem sendo aceitas. Isso abre brecha para roubo de sessão, fixação de sessão ou acesso não autorizado após logout.

Ejemplo

Um usuário faz login em um banco online e recebe um token de sessão. A aplicação não verifica se o token expirou no servidor, então mesmo após 24 horas de inatividade, aquele token continua funcional — um atacante que capturar o token pode acessar a conta indefinidamente.

Cómo mitigar

Implemente timeout rigoroso no servidor (revogue tokens expirados), valide a expiração a cada requisição, use session store confiável (Redis, BD), regenere IDs após login/logout, e considere tokens com TTL curto ou refresh tokens com rotação automática.

CVE-2026-9802MEDIUMKeycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restartEPSS 0.3%CVE-2026-34828HIGHlistmonk: Active sessions remain valid after password reset and password changeEPSS 0.3%CVE-2024-56351MEDIUMIn JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user rolesEPSS 0.3%CVE-2026-42172LOWCoolify: Sanctum API Tokens Have No Expiration — Leaked Tokens Grant Permanent AccessEPSS 0.3%CVE-2022-2888MEDIUMInsufficient Session Expiration in octoprint/octoprintEPSS 0.3%CVE-2025-57766LOWFides's Admin UI User Password Change Does Not Invalidate Current SessionEPSS 0.3%CVE-2021-3461A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity providerEPSS 0.3%CVE-2024-46892MEDIUMA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sEPSS 0.3%CVE-2024-36041HIGHKSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on EPSS 0.3%CVE-2019-3867A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access tEPSS 0.3%CVE-2026-27764MEDIUMMobiliti e-mobi.hu Insufficient Session ExpirationEPSS 0.3%CVE-2026-46656HIGHBludit CMS has improper authorization and mediation failure leading to persistent ghost sessionsEPSS 0.3%CVE-2024-32006MEDIUMA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the EPSS 0.3%CVE-2026-84480CRITICALWWBN AVideo Password Recovery Token Expiration BypassEPSS 0.3%CVE-2025-50491HIGHImproper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers tEPSS 0.3%CVE-2026-87014MEDIUMOpen WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notesEPSS 0.3%CVE-2026-44188MEDIUMAnsible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expirationEPSS 0.3%CVE-2025-22386HIGHAn issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B applicEPSS 0.3%CVE-2024-46040MEDIUMIoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation of the authenticatiEPSS 0.3%CVE-2026-25720MEDIUMSenseLive X3050 Insufficient session expirationEPSS 0.3%