Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jp3m-vh3g-6ggp

Опубликовано: 04 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Liferay Portal and Liferay DXP fails to properly import users from LDAP

Security LDAP Implementation before 2.0.16 from Liferay Portal through v7.2.1 and Liferay DXP through v7.2 does not correctly import users from LDAP, allowing remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exists in LDAP.

Пакеты

Наименование

com.liferay:com.liferay.portal.security.ldap.impl

maven
Затронутые версииВерсия исправления

< 2.0.19

2.0.19

Наименование

com.liferay.portal:release.dxp.bom

maven
Затронутые версииВерсия исправления

< 7.3.0-ga1

7.3.0-ga1

EPSS

Процентиль: 83%
0.01851
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.

EPSS

Процентиль: 83%
0.01851
Низкий

7.5 High

CVSS3