The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for user creation, which allows attackers with access to the database to obtain a user's password.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-08-03T18:33:34

Updated: 2024-08-03T23:50:42.278Z

Reserved: 2021-05-20T00:00:00

Link: CVE-2021-33325

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-08-03T19:15:08.720

Modified: 2021-08-11T14:45:01.737

Link: CVE-2021-33325

cve-icon Redhat

No data.