CVE-2021-38266 Information
Jun 07, 2022
cve
Description
The Portal Security module in Liferay Portal 7.2.1 and earlier and Liferay DXP 7.0 before fix pack 90 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
http://liferay.com https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38266 https://issues.liferay.com/browse/LPE-17191
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: