Authentication mechanism absence or evasion In com.liferay:com.liferay.portal.security.ldap.impl
Description
Liferay Portal and Liferay DXP fails to properly import users from LDAP Security LDAP Implementation before 2.0.16 from Liferay Portal through v7.2.1 and Liferay DXP through v7.2 does not correctly import users from LDAP, allowing remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exists in LDAP.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 2.0.19 | ||
maven | 7.3.0-ga1 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.