CVE-2021-29047: High severity Liferay DXP vulnerability
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.fp1 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.3.6 - Upgrade
Upgrade
Liferay Portalto a version that resolves this vulnerability.Fixed in 7.3.4 - Upgrade
Upgrade
Liferay Portalto a version that resolves this vulnerability.Fixed in 7.3.5 - Upgrade
Upgrade
Liferay DXPto a version that resolves this vulnerability.Fixed in 7.3
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29047?
CVE-2021-29047 is rated as a medium severity vulnerability due to its potential for abuse in bypassing CAPTCHA protections.
How do I fix CVE-2021-29047?
To fix CVE-2021-29047, upgrade to Liferay Portal 7.3.6 or later versions including Liferay DXP 7.3 with fix pack 1.
What does CVE-2021-29047 affect?
CVE-2021-29047 affects Liferay Portal versions 7.3.4 and 7.3.5, as well as Liferay DXP 7.3 prior to fix pack 1.
What is the impact of CVE-2021-29047?
The impact of CVE-2021-29047 allows remote attackers to reuse CAPTCHA answers, enabling them to bypass security measures.
Is CVE-2021-29047 remotely exploitable?
Yes, CVE-2021-29047 is remotely exploitable, allowing attackers to perform protected actions by reusing CAPTCHA responses.