CVE-2021-33338: CSRF
The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in URLs, which allows man-in-the-middle attackers to obtain the token and conduct Cross-Site Request Forgery (CSRF) attacks via the pauth parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-33338.
What is the severity level of CVE-2021-33338?
The severity level of CVE-2021-33338 is high, with a severity value of 7.5.
Which software versions are affected by CVE-2021-33338?
CVE-2021-33338 affects Liferay Portal versions 7.1.0 through 7.3.2 and Liferay DXP versions 7.1 before fix pack 19 and 7.2 before fix pack 6.
What is the impact of CVE-2021-33338?
CVE-2021-33338 allows man-in-the-middle attackers to conduct Cross-Site Request Forgery (CSRF) attacks by obtaining the CSRF token from the exposed p_auth parameter in URLs.
How can I fix CVE-2021-33338?
To fix CVE-2021-33338, you should apply the relevant fix packs for Liferay DXP or Liferay Portal as mentioned in the provided references.