CVE-2021-29038

MEDIUM

Liferay Digital Experience Platform < 7.2 - Password Reset Weakness

Title source: rule
STIX 2.1

Description

Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers.

Scores

CVSS v3 6.3
EPSS 0.0009
EPSS Percentile 26.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-640
Status published
Products (9)
com.liferay/com.liferay.login.web 0 - 5.0.18Maven
com.liferay/com.liferay.users.admin.web 0 - 5.0.33Maven
com.liferay.commerce/com.liferay.commerce.account.web 0 - 3.0.7Maven
com.liferay.portal/portal-impl 0 - 5.18.4Maven
com.liferay.portal/release.dxp.bom 0 - 7.2.10.fp17Maven
liferay/digital_experience_platform 7.2 (17 CPE variants)
liferay/digital_experience_platform 7.3
liferay/digital_experience_platform < 7.2
liferay/liferay_portal < 7.2.1
Published Feb 20, 2024
Tracked Since Feb 18, 2026