CVE-2021-29041

MEDIUM

Liferay DXP < 7.3 - Authenticated Denial of Service via Multi-Factor Authentication TOTP Manipulation

Title source: llm
STIX 2.1

Description

Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated attackers to prevent any user from authenticating by (1) enabling Time-based One-time password (TOTP) on behalf of the other user or (2) modifying the other user's TOTP shared secret.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
http://liferay.com
Issue Tracking, Vendor Advisory x_refsource_misc
https://issues.liferay.com/browse/LPE-17131

Scores

CVSS v3 6.5
EPSS 0.0051
EPSS Percentile 66.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (3)
com.liferay.portal/release.dxp.bom 0 - 7.3.10.fp1Maven
liferay/dxp 7.3
liferay/dxp < 7.3
Published May 16, 2021
Tracked Since Feb 18, 2026