CVE-2022-41414: Medium severity Liferay Liferay Portal vulnerability
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:com.liferay.portal.implto a version that resolves this vulnerability.Fixed in 8.0.0 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.2-ga3
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41414?
CVE-2022-41414 has a medium severity level due to the risk of username and site enumeration.
How do I fix CVE-2022-41414?
To fix CVE-2022-41414, update Liferay Portal to a version after 7.4.2 that addresses this security issue.
What versions of Liferay Portal are affected by CVE-2022-41414?
CVE-2022-41414 affects Liferay Portal versions from 7.0.0 to 7.4.2.
What types of attacks are possible with CVE-2022-41414?
CVE-2022-41414 allows attackers to enumerate usernames, site names, and pages on the affected Liferay Portal installations.
How can I mitigate the risks associated with CVE-2022-41414?
Mitigating the risks associated with CVE-2022-41414 involves disabling the insecure default configuration and upgrading to a secure version of Liferay Portal.