PT-2024-10915 · Liferay · Liferay Portal+1
Duracell80
·
Published
2024-02-20
·
Updated
2025-05-13
·
CVE-2021-29038
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Liferay Portal versions 7.2.0 through 7.3.5
Liferay DXP 7.3 before fix pack 1
Liferay DXP 7.2 before fix pack 17
Description
The issue allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers because password reminder answers are not obfuscated on the page.
Recommendations
For Liferay Portal versions 7.2.0 through 7.3.5, update to a version that includes the fix for this issue.
For Liferay DXP 7.3, apply fix pack 1 or later.
For Liferay DXP 7.2, apply fix pack 17 or later.
As a temporary workaround, consider implementing additional security measures to protect against man-in-the-middle and shoulder surfing attacks, such as using HTTPS and educating users about the risks of using public computers or public networks to access sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liferay Dxp
Liferay Portal