CVE-2021-29041: Medium severity Liferay DXP vulnerability
Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated attackers to prevent any user from authenticating by (1) enabling Time-based One-time password (TOTP) on behalf of the other user or (2) modifying the other user's TOTP shared secret.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.fp1
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29041?
CVE-2021-29041 is classified as a denial-of-service (DoS) vulnerability.
How do I fix CVE-2021-29041?
To fix CVE-2021-29041, upgrade Liferay DXP to version 7.3 fix pack 1 or later.
What impact does CVE-2021-29041 have on Liferay DXP users?
CVE-2021-29041 enables remote authenticated attackers to prevent user authentication through manipulation of multi-factor authentication settings.
Which versions of Liferay DXP are affected by CVE-2021-29041?
CVE-2021-29041 affects all versions of Liferay DXP prior to 7.3 fix pack 1.
Can CVE-2021-29041 be exploited remotely?
Yes, CVE-2021-29041 can be exploited by remote authenticated attackers.