The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack password hashes.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published: 2024-02-20T09:17:04.894Z

Updated: 2024-08-01T23:44:09.762Z

Reserved: 2024-02-08T13:57:11.425Z

Link: CVE-2024-25607

cve-icon Vulnrichment

Updated: 2024-08-01T23:44:09.762Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-20T10:15:08.333

Modified: 2024-02-20T19:50:53.960

Link: CVE-2024-25607

cve-icon Redhat

No data.