logo

CVE-2021-29043 com.liferay.portal:release.dxp.bom

Package

Manager: maven
Name: com.liferay.portal:release.dxp.bom
Vulnerable Version: >=0 <7.0.10.fp97 || >=7.1.0 <7.1.10.fp21 || >=7.2.0 <7.2.10.fp10 || >=7.3.0 <7.3.10.fp1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00204 pctl0.42693

Details

Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing.

Metadata

Created: 2022-05-24T19:02:39Z
Modified: 2025-05-28T20:10:38Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xx2h-2hf5-v7vv/GHSA-xx2h-2hf5-v7vv.json
CWE IDs: ["CWE-200", "CWE-522"]
Alternative ID: GHSA-xx2h-2hf5-v7vv
Finding: F017
Auto approve: 1