Логотип exploitDog
bind:CVE-2022-42132
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-42132

Количество 2

Количество 2

nvd логотип

CVE-2022-42132

около 3 лет назад

The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-f43m-hhj4-q3jg

около 3 лет назад

Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-42132

The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-f43m-hhj4-q3jg

Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL

CVSS3: 5.9
0%
Низкий
около 3 лет назад

Уязвимостей на страницу