CVE-2021-33321
published 2021-08-03CVE-2021-33321: Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.42%
69.9th percentile
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.password should be defaulted to true.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | dxp | < 7.3 | 7.3 |
| liferay | liferay_portal | >= 6.2.3 < 7.3.3 | 7.3.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Liferay Portal and Liferay DXP insecure default configuration
osv·2022-05-24
CVE-2021-33321 [HIGH] Liferay Portal and Liferay DXP insecure default configuration
Liferay Portal and Liferay DXP insecure default configuration
Insecure default configuration in portal services implementation before 5.11.0 in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.password should be defaulted to true.
GHSA
Liferay Portal and Liferay DXP insecure default configuration
ghsa·2022-05-24
CVE-2021-33321 [HIGH] CWE-640 Liferay Portal and Liferay DXP insecure default configuration
Liferay Portal and Liferay DXP insecure default configuration
Insecure default configuration in portal services implementation before 5.11.0 in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.password should be defaulted to true.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://help.liferay.com/hc/en-us/articles/360050785632https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120748055https://help.liferay.com/hc/en-us/articles/360050785632https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120748055
2021-08-03
Published