Fallos del tipo CWE-613

472 resultados

Expiração de Sessão Inadequada

A aplicação não valida ou reforça corretamente o tempo de vida de uma sessão de usuário, permitindo que sessões expiradas ou mal gerenciadas continuem sendo aceitas. Isso abre brecha para roubo de sessão, fixação de sessão ou acesso não autorizado após logout.

Ejemplo

Um usuário faz login em um banco online e recebe um token de sessão. A aplicação não verifica se o token expirou no servidor, então mesmo após 24 horas de inatividade, aquele token continua funcional — um atacante que capturar o token pode acessar a conta indefinidamente.

Cómo mitigar

Implemente timeout rigoroso no servidor (revogue tokens expirados), valide a expiração a cada requisição, use session store confiável (Redis, BD), regenere IDs após login/logout, e considere tokens com TTL curto ou refresh tokens com rotação automática.

CVE-2022-2713HIGHInsufficient Session Expiration in cockpit-hq/cockpitEPSS 1.2%CVE-2022-31050MEDIUMInsufficient Session Expiration in TYPO3 Admin ToolEPSS 1.2%CVE-2022-2064CRITICALInsufficient Session Expiration in nocodb/nocodbEPSS 1.2%CVE-2024-22543MEDIUMAn issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET reEPSS 1.2%CVE-2022-23063HIGHShopizer - Insufficient Session ExpirationEPSS 1.2%CVE-2023-31065CRITICALApache InLong: Insufficient Session Expiration in InLongEPSS 1.2%CVE-2021-36330HIGHDell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attaEPSS 1.2%CVE-2020-1762HIGHAn insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a reEPSS 1.2%CVE-2024-50562MEDIUMAn Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and belEPSS 1.1%CVE-2021-25979CRITICALApostrophe - Insufficient Session ExpirationEPSS 1.1%CVE-2025-24859LOWApache Roller: Insufficient Session Expiration on Password ChangeEPSS 1.1%CVE-2018-1127MEDIUMTendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain aEPSS 1.1%CVE-2021-42545HIGHInsufficient Session Expiration in TopEaseEPSS 1.1%CVE-2020-15269HIGHExpired token reuse in SpreeEPSS 1.1%CVE-2021-25966HIGHOrchard Core CMS - Improper Session Termination after Password ChangeEPSS 1.1%CVE-2017-3215The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with aEPSS 1.0%CVE-2021-35034HIGHAn insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access thEPSS 1.0%CVE-2022-22113HIGHDayByDay CRM - Insufficient Session Expiration after Password ChangeEPSS 1.0%CVE-2023-24426HIGHJenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login.EPSS 1.0%CVE-2022-0991HIGHInsufficient Session Expiration in admidio/admidioEPSS 1.0%