CVE-2022-41414
published 2022-10-07CVE-2022-41414: An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and…
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.44%
35.6th percentile
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | liferay_portal | 7.0.0 – 7.4.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
osv·2022-10-07
CVE-2022-41414 [MEDIUM] Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
GHSA
Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
ghsa·2022-10-07
CVE-2022-41414 [MEDIUM] CWE-276 Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-07
Published