Authentication mechanism absence or evasion In com.liferay:com.liferay.portal.security.ldap.impl

Description

Liferay Portal and Liferay DXP fails to properly import users from LDAP Security LDAP Implementation before 2.0.16 from Liferay Portal through v7.2.1 and Liferay DXP through v7.2 does not correctly import users from LDAP, allowing remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exists in LDAP.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions