CVE-2022-41414
published 2022-10-07CVE-2022-41414: An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and…
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.46%
38.2th percentile
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | liferay_portal | 7.0.0 – 7.4.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Liferay Portal up to 7.4.2 auth.login.prompt.enabled information disclosure (EUVD-2022-44607)
vuldb·2026-08-04·CVSS 5.3
CVE-2022-41414 [MEDIUM] Liferay Portal up to 7.4.2 auth.login.prompt.enabled information disclosure (EUVD-2022-44607)
A vulnerability was found in Liferay Portal up to 7.4.2. It has been classified as problematic. Affected is an unknown function of the component auth.login.prompt.enabled. The manipulation leads to information disclosure.
This vulnerability is documented as CVE-2022-41414. The attack requires being on the local network. There is not any exploit available.
OSV
Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
osv·2022-10-07
CVE-2022-41414 [MEDIUM] Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
GHSA
Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
ghsa·2022-10-07
CVE-2022-41414 [MEDIUM] CWE-276 Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-07
Published