CWE-613: Insufficient Session Expiration
| Abstraction | Structure | Status |
|---|---|---|
| None | Simple | Incomplete |
Description
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Related Weaknesses
| Nature | ID | View ID | Name |
|---|---|---|---|
| ChildOf | CWE-672 | 1000 | Operation on a Resource after Expiration or Release |
| ChildOf | CWE-672 | 1003 | Operation on a Resource after Expiration or Release |
| CanPrecede | CWE-287 | 1000 | Improper Authentication |
Modes of Introduction
| Phase | Note |
|---|---|
| Architecture and Design | - |
| Implementation | REALIZATION: This weakness is caused during implementation of an architectural security tactic. |
Applicable Platforms
Languages
Class: Not Language-Specific
Technologies
Class: Web Based Class: None
Common Consequences
| Scope | Impact | Note |
|---|---|---|
| Access Control | Bypass Protection Mechanism |
Detection Methods
Automated Static Analysis
Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect “sources” (origins of input) with “sinks” (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Effectiveness: High
Potential Mitigations
Implementation
Set sessions/credentials expiration date.