PT-2022-25851 · Liferay · Liferay Portal

Published

2022-10-07

·

Updated

2022-10-11

·

CVE-2022-41414

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.0.0 through 7.4.2
Description The issue is related to an insecure default in the auth.login.prompt.enabled component, which allows attackers to enumerate usernames, site names, and pages.
Recommendations For Liferay Portal versions 7.0.0 through 7.4.2, consider disabling the auth.login.prompt.enabled component to prevent username, site name, and page enumeration until a patch is available.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2022-41414
GHSA-9427-7F65-88C8

Affected Products

Liferay Portal