Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mx7-xvfg-fg53

Опубликовано: 08 фев. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

Liferay Portal's account lockout does not invalidate existing user sessions

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

>= 7.2.0, < 7.3.1

7.3.1

Наименование

com.liferay.portal:release.dxp.bom

maven
Затронутые версииВерсия исправления

>= 7.2.0, < 7.2.10.fp5

7.2.10.fp5

EPSS

Процентиль: 40%
0.00186
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.

EPSS

Процентиль: 40%
0.00186
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-384