Security Advisory

CVE-2021-38266

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-03-02 23:00:44
Last updated 2024-08-04 01:37:16
Assigner mitre
State PUBLISHED

Description

The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.