COMMON WEAKNESS ENUMERATIONIncomplete

CWE-613

Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Abstraction

Base

Structure

Simple

Likelihood of Exploit

Medium

Understand the problem

What is the problem?

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Root cause

How and when does the problem arise?

Lifecycle phase

Architecture and Design

Lifecycle phase

Implementation

REALIZATION: This weakness is caused during implementation of an architectural security tactic.

Risk

What does successful exploitation lead to?

Bypass Protection Mechanism

Affected security scopes: Access Control

Defence

How is it prevented and fixed?

Implementation

Implementation-phase defence

Detail
Set sessions/credentials expiration date.

Verification

How is it detected?

Automated Static Analysis

High
Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)