Description
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.
Published: 2022-11-15
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-45209 Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
Github GHSA Github GHSA GHSA-f43m-hhj4-q3jg Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
History

Wed, 30 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Liferay Digital Experience Platform Liferay Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-30T14:18:27.784Z

Reserved: 2022-10-03T00:00:00.000Z

Link: CVE-2022-42132

cve-icon Vulnrichment

Updated: 2024-08-03T13:03:45.198Z

cve-icon NVD

Status : Modified

Published: 2022-11-15T02:15:12.240

Modified: 2025-04-30T15:15:56.963

Link: CVE-2022-42132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses