CVE-2021-29043 – com.liferay.portal:release.dxp.bom
Package
Manager: maven
Name: com.liferay.portal:release.dxp.bom
Vulnerable Version: >=0 <7.0.10.fp97 || >=7.1.0 <7.1.10.fp21 || >=7.2.0 <7.2.10.fp10 || >=7.3.0 <7.3.10.fp1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00204 pctl0.42693
Details
Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing.
Metadata
Created: 2022-05-24T19:02:39Z
Modified: 2025-05-28T20:10:38Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xx2h-2hf5-v7vv/GHSA-xx2h-2hf5-v7vv.json
CWE IDs: ["CWE-200", "CWE-522"]
Alternative ID: GHSA-xx2h-2hf5-v7vv
Finding: F017
Auto approve: 1