Total
472 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-38489 | 1 Getkirby | 1 Kirby | 2024-11-21 | N/A | 7.3 HIGH |
|
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). It can only be abused if a Kirby user is logged in on a device or browser that is shared with potentially untrusted users or if an attacker already maliciously used a previous password to log in to a Kirby site as the affected user.
Insufficient Session Expiration is when a w ...
Show More |
|||||
| CVE-2023-37919 | 1 Cal | 1 Cal.com | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain active even after enabling 2FA. When activating 2FA on a Cal.com account that is logged in on two or more devices, the account stays logged in on the other device(s) stays logged in without having to verify the account owner's identity. As of time of publication, no known patches or workarounds exist.
|
|||||
| CVE-2023-37570 | 1 Esds.co | 1 Emagic Data Center Management | 2024-11-21 | N/A | 7.2 HIGH |
|
This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie.
By reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system.
|
|||||
| CVE-2023-37504 | 1 Hcltech | 1 Hcl Compass | 2024-11-21 | N/A | 7.1 HIGH |
|
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user.
|
|||||
| CVE-2023-35857 | 1 Siren | 1 Investigate | 2024-11-21 | N/A | 9.8 CRITICAL |
|
In Siren Investigate before 13.2.2, session keys remain active even after logging out.
|
|||||
| CVE-2023-33303 | 1 Fortinet | 1 Fortiedr | 2024-11-21 | N/A | 8.1 HIGH |
|
A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request
|
|||||
| CVE-2023-32318 | 1 Nextcloud | 1 Nextcloud Server | 2024-11-21 | N/A | 7.2 HIGH |
|
Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After successfully authenticating with any other account the previous session would be continued and the attacker would be authenticated as the previously logged in user. It is recommended that the Nextcloud Server is upgraded to 25.0.6 or 26.0.1.
|
|||||
| CVE-2023-31140 | 1 Openproject | 1 Openproject | 2024-11-21 | N/A | 4.8 MEDIUM |
|
OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a user registers and confirms their first two-factor authentication (2FA) device for an account, existing logged in sessions for that user account are not terminated. Likewise, if an administrators creates a mobile phone 2FA device on behalf of a user, their existing sessions are not terminated. The issue has been resolved in OpenProject version 12.5.4 by actively terminating ses ...
Show More |
|||||
| CVE-2023-31139 | 1 Dhis2 | 1 Dhis 2 | 2024-11-21 | N/A | 4.3 MEDIUM |
|
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.37 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.1.2, Personal Access Tokens (PATs) generate unrestricted session cookies. This may lead to a bypass of other access restrictions (for example, based on allowed IP addresses or HTTP methods). DHIS2 implementers should upgrade to a supported version of DHIS2: 2.37.9.1, 2.38.3.1, or 2.39.1.2. Implementers can work around ...
Show More |
|||||
| CVE-2023-31065 | 1 Apache | 1 Inlong | 2024-11-21 | N/A | 9.1 CRITICAL |
|
Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.
An old session can be used by an attacker even after the user has been deleted or the password has been changed.
Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7836 https://github.com/apache/inlong/pull/7836 , https://github.com/apache/inlong/pull/7884 https://github.com/apache/inlo ...
Show More |
|||||
| CVE-2023-2788 | 1 Mattermost | 1 Mattermost | 2024-11-21 | N/A | 6.2 MEDIUM |
|
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.
|
|||||
| CVE-2023-28003 | 1 Schneider-electric | 1 Ecostruxure Power Monitoring Expert | 2024-11-21 | N/A | 6.7 MEDIUM |
|
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to
maintain unauthorized access over a hijacked session in PME after the legitimate user has
signed out of their account.
|
|||||
| CVE-2023-28001 | 1 Fortinet | 1 Fortios | 2024-11-21 | N/A | 4.1 MEDIUM |
|
An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via reusing the session of a deleted user in the REST API.
|
|||||
| CVE-2023-27891 | 1 Rami | 1 Pretix | 2024-11-21 | N/A | 7.5 HIGH |
|
rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.
|
|||||
| CVE-2023-26288 | 1 Ibm | 1 Aspera Orchestrator | 2024-11-21 | N/A | 5.5 MEDIUM |
|
IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 248477.
|
|||||
| CVE-2023-23929 | 1 Vantage6 | 1 Vantage6 | 2024-11-21 | N/A | 8.8 HIGH |
|
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a validity of 24-48 hours. A fix was released in version 3.8.0.
|
|||||
| CVE-2023-23614 | 1 Pi-hole | 1 Web Interface | 2024-11-21 | N/A | 8.8 HIGH |
|
Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Remember me for 7 days" cookie value makes it possible for an attacker to "pass the hash" to login or reuse a theoretically expired "remember me" cookie. It also exposes the hash over the network and stores it unnecessarily in the browser. The cookie itself is set ...
Show More |
|||||
| CVE-2023-22771 | 1 Arubanetworks | 24 7010, 7030, 7205 and 21 more | 2024-11-21 | N/A | 6.8 MEDIUM |
|
An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account
|
|||||
| CVE-2023-22732 | 1 Shopware | 1 Shopware | 2024-11-21 | N/A | 3.7 LOW |
|
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In version 6.4.18.1 an automatic logout into the Administration session has been added. As a result the user will be logged out when they are inactive. Users are advised to upgrade. There are no known workarounds for this issue.
|
|||||
| CVE-2023-22591 | 1 Ibm | 2 Robotic Process Automation, Robotic Process Automation As A Service | 2024-11-21 | N/A | 3.9 LOW |
|
IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. IBM X-Force ID: 243710.
|
|||||
| CVE-2023-22492 | 1 Zitadel | 1 Zitadel | 2024-11-21 | N/A | 5.9 MEDIUM |
|
ZITADEL is a combination of Auth0 and Keycloak. RefreshTokens is an OAuth 2.0 feature that allows applications to retrieve new access tokens and refresh the user's session without the need for interacting with a UI. RefreshTokens were not invalidated when a user was locked or deactivated. The deactivated or locked user was able to obtain a valid access token only through a refresh token grant. When the locked or deactivated user’s session was already terminated (“logged out”) then it was not pos ...
Show More |
|||||
| CVE-2023-1854 | 1 Online Graduate Tracer System Project | 1 Online Graduate Tracer System | 2024-11-21 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file admin/. The manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-224994 is the identifier assigned to this vulnerability.
|
|||||
| CVE-2023-1788 | 1 Firefly-iii | 1 Firefly Iii | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.
|
|||||
| CVE-2023-1543 | 1 Answer | 1 Answer | 2024-11-21 | N/A | 8.8 HIGH |
|
Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.
|
|||||
| CVE-2023-0227 | 1 Pyload | 1 Pyload | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.
|
|||||
| CVE-2023-0041 | 2 Ibm, Linux | 2 Security Guardium, Linux Kernel | 2024-11-21 | N/A | 6.3 MEDIUM |
|
IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-Force ID: 243657.
|
|||||
| CVE-2022-4070 | 1 Librenms | 1 Librenms | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.
|
|||||
| CVE-2022-48317 | 1 Checkmk | 1 Checkmk | 2024-11-21 | N/A | 5.6 MEDIUM |
|
Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when communicating with the RestAPI.
|
|||||
| CVE-2022-46177 | 1 Discourse | 1 Discourse | 2024-11-21 | N/A | 5.7 MEDIUM |
|
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, when a user requests for a password reset link email, then changes their primary email, the old reset email is still valid. When the old reset email is used to reset the password, the Discourse account's primary email would be re-linked to the old email. If the old email address is compromised or has transferred ownership, this lead ...
Show More |
|||||
| CVE-2022-41672 | 1 Apache | 1 Airflow | 2024-11-21 | N/A | 8.1 HIGH |
|
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.
|
|||||
| CVE-2022-41291 | 3 Ibm, Linux, Microsoft | 4 Aix, Infosphere Information Server, Linux Kernel and 1 more | 2024-11-21 | N/A | 6.5 MEDIUM |
|
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699.
|
|||||
| CVE-2022-40228 | 1 Ibm | 1 Datapower Gateway | 2024-11-21 | N/A | 3.7 LOW |
|
IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235527.
|
|||||
| CVE-2022-3916 | 1 Redhat | 7 Enterprise Linux, Keycloak, Openshift Container Platform and 4 more | 2024-11-21 | N/A | 6.8 MEDIUM |
|
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authenticated user; when utilizing the refresh token, they will be issued a token for the original user.
|
|||||
| CVE-2022-3867 | 1 Hashicorp | 1 Nomad | 2024-11-21 | N/A | 2.7 LOW |
|
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
|
|||||
| CVE-2022-3362 | 1 Ikus-soft | 1 Rdiffweb | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.
|
|||||
| CVE-2022-3080 | 2 Fedoraproject, Isc | 2 Fedora, Bind | 2024-11-21 | N/A | 7.5 HIGH |
|
By sending specific queries to the resolver, an attacker can cause named to crash.
|
|||||
| CVE-2022-39234 | 1 Glpi-project | 1 Glpi | 2024-11-21 | N/A | 4.7 MEDIUM |
|
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Deleted/deactivated user could continue to use their account as long as its cookie is valid. This issue has been patched, please upgrade to version 10.0.4. There are currently no known workarounds.
|
|||||
| CVE-2022-38707 | 1 Ibm | 1 Cognos Command Center | 2024-11-21 | N/A | 4.0 MEDIUM |
|
IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.
|
|||||
| CVE-2022-35728 | 1 F5 | 12 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Analytics and 9 more | 2024-11-21 | N/A | 8.1 HIGH |
|
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain valid for a limited time after logging out from the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
|
|||||
| CVE-2022-34624 | 1 Mealie | 1 Mealie | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
|
|||||