CVE-2021-29038

MEDIUM

Liferay Portal 7.2.0-7.3.5 and Liferay DXP < 7.3 FP1 - Password Reminder Answer Exposure

Title source: llm
STIX 2.1

Description

Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers.

Scores

CVSS v3 6.3
EPSS 0.0028
EPSS Percentile 19.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-640
Status published
Products (9)
com.liferay/com.liferay.login.web 0 - 5.0.18Maven
com.liferay/com.liferay.users.admin.web 0 - 5.0.33Maven
com.liferay.commerce/com.liferay.commerce.account.web 0 - 3.0.7Maven
com.liferay.portal/portal-impl 0 - 5.18.4Maven
com.liferay.portal/release.dxp.bom 0 - 7.2.10.fp17Maven
liferay/digital_experience_platform 7.2 (17 CPE variants)
liferay/digital_experience_platform 7.3
liferay/digital_experience_platform < 7.2
liferay/liferay_portal < 7.2.1
Published Feb 20, 2024
Tracked Since Feb 18, 2026