Description
Setting a Servlet session’s setMaxInactiveInterval to 0 or a negative value disables expiration due to inactivity. Long-lived login sessions may let stolen session IDs remain usable or leave account access available on shared devices and unattended browsers.
Potential impact
- Prolonged reuse of a stolen session ID
- Continued access to an account left signed in on a shared device
- Continued access to sensitive functions with an existing session if no separate reauthentication is required
Remediation
- Set a positive inactivity interval in seconds that suits the application’s requirements.
- Use shorter timeouts and reauthentication for high-risk functions.
- Invalidate the session and expire its cookie on logout.
Examples
These method excerpts configure an existing HttpSession. Apply an absolute session lifetime and reauthentication for important actions through separate policies.
Before
java
void login(HttpSession session) {
session.setMaxInactiveInterval(-30);
}
After
java
void login(HttpSession session) {
session.setMaxInactiveInterval(900);
}
Explanation:
- Before: A value of zero or less prevents expiration even when the session is inactive.
- After: Sets an inactivity limit of 900 seconds (15 minutes). Ongoing requests can keep the session active, so this alone does not bound its total lifetime.