Description
Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated attackers to prevent any user from authenticating by (1) enabling Time-based One-time password (TOTP) on behalf of the other user or (2) modifying the other user's TOTP shared secret.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15687 | Liferay DXP Vulnerable to Denial-of-service (DoS) in the Multi-Factor Authentication Module |
Github GHSA |
GHSA-82j7-2h3j-hc7f | Liferay DXP Vulnerable to Denial-of-service (DoS) in the Multi-Factor Authentication Module |
References
| Link | Providers |
|---|---|
| http://liferay.com |
|
| https://issues.liferay.com/browse/LPE-17131 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T21:55:12.504Z
Reserved: 2021-03-22T00:00:00.000Z
Link: CVE-2021-29041
No data.
Status : Modified
Published: 2021-05-16T16:15:07.260
Modified: 2024-11-21T06:00:34.730
Link: CVE-2021-29041
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA