← Back

CVE-2021-38266

nvd nist
Published: Mar 2, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.

Affected (113)

2 products
Liferay Portal
Digital Experience Platform
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 7.2.1
Configuration B
112 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.0
Version 7.0 fix_pack_10
Version 7.0 fix_pack_11
Version 7.0 fix_pack_12
Version 7.0 fix_pack_13
Version 7.0 fix_pack_14
Version 7.0 fix_pack_15
Version 7.0 fix_pack_16
Version 7.0 fix_pack_17
Version 7.0 fix_pack_18
Version 7.0 fix_pack_19
Version 7.0 fix_pack_1
Version 7.0 fix_pack_20
Version 7.0 fix_pack_21
Version 7.0 fix_pack_22
Version 7.0 fix_pack_23
Version 7.0 fix_pack_24
Version 7.0 fix_pack_25
Version 7.0 fix_pack_26
Version 7.0 fix_pack_27
Version 7.0 fix_pack_28
Version 7.0 fix_pack_29
Version 7.0 fix_pack_2
Version 7.0 fix_pack_30
Version 7.0 fix_pack_31
Version 7.0 fix_pack_32
Version 7.0 fix_pack_33
Version 7.0 fix_pack_34
Version 7.0 fix_pack_35
Version 7.0 fix_pack_36
Version 7.0 fix_pack_37
Version 7.0 fix_pack_38
Version 7.0 fix_pack_39
Version 7.0 fix_pack_3
Version 7.0 fix_pack_40
Version 7.0 fix_pack_41
Version 7.0 fix_pack_42
Version 7.0 fix_pack_43
Version 7.0 fix_pack_44
Version 7.0 fix_pack_45
Version 7.0 fix_pack_46
Version 7.0 fix_pack_47
Version 7.0 fix_pack_48
Version 7.0 fix_pack_49
Version 7.0 fix_pack_4
Version 7.0 fix_pack_50
Version 7.0 fix_pack_51
Version 7.0 fix_pack_52
Version 7.0 fix_pack_53
Version 7.0 fix_pack_54
Version 7.0 fix_pack_55
Version 7.0 fix_pack_56
Version 7.0 fix_pack_57
Version 7.0 fix_pack_58
Version 7.0 fix_pack_59
Version 7.0 fix_pack_5
Version 7.0 fix_pack_60
Version 7.0 fix_pack_61
Version 7.0 fix_pack_62
Version 7.0 fix_pack_63
Version 7.0 fix_pack_64
Version 7.0 fix_pack_65
Version 7.0 fix_pack_66
Version 7.0 fix_pack_67
Version 7.0 fix_pack_68
Version 7.0 fix_pack_69
Version 7.0 fix_pack_6
Version 7.0 fix_pack_70
Version 7.0 fix_pack_71
Version 7.0 fix_pack_72
Version 7.0 fix_pack_73
Version 7.0 fix_pack_74
Version 7.0 fix_pack_75
Version 7.0 fix_pack_76
Version 7.0 fix_pack_77
Version 7.0 fix_pack_78
Version 7.0 fix_pack_79
Version 7.0 fix_pack_7
Version 7.0 fix_pack_80
Version 7.0 fix_pack_81
Version 7.0 fix_pack_82
Version 7.0 fix_pack_83
Version 7.0 fix_pack_84
Version 7.0 fix_pack_85
Version 7.0 fix_pack_86
Version 7.0 fix_pack_87
Version 7.0 fix_pack_88
Version 7.0 fix_pack_89
Version 7.0 fix_pack_8
Version 7.0 fix_pack_9
Version 7.1
Version 7.1 fix_pack_10
Version 7.1 fix_pack_11
Version 7.1 fix_pack_12
Version 7.1 fix_pack_13
Version 7.1 fix_pack_14
Version 7.1 fix_pack_15
Version 7.1 fix_pack_16
Version 7.1 fix_pack_1
Version 7.1 fix_pack_2
Version 7.1 fix_pack_3
Version 7.1 fix_pack_4
Version 7.1 fix_pack_5
Version 7.1 fix_pack_6
Version 7.1 fix_pack_7
Version 7.1 fix_pack_8
Version 7.1 fix_pack_9
Version 7.2
Version 7.2 fix_pack_1
Version 7.2 fix_pack_2
Version 7.2 fix_pack_3
Version 7.2 fix_pack_4

References (6)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.