CVE-2023-47798Session Fixation in Digital Experience Platform

CWE-384Session Fixation4 documents4 sources
Severity
4.6MEDIUMNVD
CNA5.4
EPSS
0.2%
top 59.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8

Description

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:NExploitability: 2.1 | Impact: 2.5

Affected Packages4 packages

NVDliferay/liferay_portal7.2.07.3.0
CVEListV5liferay/portal7.2.07.3.0
CVEListV5liferay/dxp7.2.107.2.10-dxp-4

🔴Vulnerability Details

3
CVEList
CVE-2023-47798: Account lockout in Liferay Portal 72024-02-08
OSV
Liferay Portal's account lockout does not invalidate existing user sessions2024-02-08
GHSA
Liferay Portal's account lockout does not invalidate existing user sessions2024-02-08
CVE-2023-47798 — Session Fixation | cvebase