CVE-2021-29047
published 2021-05-16CVE-2021-29047: The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.06%
60.7th percentile
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | dxp | < 7.3 | 7.3 |
| liferay | dxp | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use
ghsa·2022-05-24
CVE-2021-29047 [HIGH] CWE-287 Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use
Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.
OSV
Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use
osv·2022-05-24
CVE-2021-29047 [HIGH] Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use
Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-16
Published