The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-45209 | Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL |
Github GHSA |
GHSA-f43m-hhj4-q3jg | Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-30T14:18:27.784Z
Reserved: 2022-10-03T00:00:00.000Z
Link: CVE-2022-42132
Updated: 2024-08-03T13:03:45.198Z
Status : Modified
Published: 2022-11-15T02:15:12.240
Modified: 2025-04-30T15:15:56.963
Link: CVE-2022-42132
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA