Falhas do tipo CWE-613

474 resultados

Expiração de Sessão Inadequada

Ocorre quando uma aplicação não encerra ou valida corretamente a sessão de um usuário após um período de inatividade ou quando deveria invalidá-la. Um atacante pode reutilizar um token de sessão expirado ou abandonado para se passar pelo usuário legítimo, contornando autenticação.

Exemplo

Um usuário faz login em um banco online, depois sai do navegador sem fazer logout. Horas depois, alguém acessa o histórico do navegador, encontra o cookie de sessão ainda válido e consegue acessar a conta bancária sem inserir credenciais novamente.

Como mitigar

Implemente timeout de sessão no servidor (invalide a sessão após X minutos de inatividade), force novo login em operações sensíveis, use tokens com expiração explícita (JWT com exp claim) e limpe cookies/tokens no logout. Sempre valide a sessão no lado do servidor antes de processar requisições.

CVE-2026-9802MEDIUMKeycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restartEPSS 0.3%CVE-2026-34828HIGHlistmonk: Active sessions remain valid after password reset and password changeEPSS 0.3%CVE-2024-56351MEDIUMIn JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user rolesEPSS 0.3%CVE-2026-42172LOWCoolify: Sanctum API Tokens Have No Expiration — Leaked Tokens Grant Permanent AccessEPSS 0.3%CVE-2022-2888MEDIUMInsufficient Session Expiration in octoprint/octoprintEPSS 0.3%CVE-2025-57766LOWFides's Admin UI User Password Change Does Not Invalidate Current SessionEPSS 0.3%CVE-2021-3461A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity providerEPSS 0.3%CVE-2024-46892MEDIUMA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sEPSS 0.3%CVE-2024-36041HIGHKSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on EPSS 0.3%CVE-2019-3867A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access tEPSS 0.3%CVE-2026-27764MEDIUMMobiliti e-mobi.hu Insufficient Session ExpirationEPSS 0.3%CVE-2026-46656HIGHBludit CMS has improper authorization and mediation failure leading to persistent ghost sessionsEPSS 0.3%CVE-2024-32006MEDIUMA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the EPSS 0.3%CVE-2026-84480CRITICALWWBN AVideo Password Recovery Token Expiration BypassEPSS 0.3%CVE-2025-50491HIGHImproper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers tEPSS 0.3%CVE-2026-87014MEDIUMOpen WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notesEPSS 0.3%CVE-2026-44188MEDIUMAnsible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expirationEPSS 0.3%CVE-2025-22386HIGHAn issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B applicEPSS 0.3%CVE-2024-46040MEDIUMIoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation of the authenticatiEPSS 0.3%CVE-2026-25720MEDIUMSenseLive X3050 Insufficient session expirationEPSS 0.3%