CVE-2023-33949: High severity Liferay Digital Experience Platform vulnerability
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property company.security.strangers.verify should be set to true.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.3.1 - Configuration
Set the Liferay portal property `company.security.strangers.verify` to `true` (for Liferay Portal 7.3.0 and earlier and Liferay DXP 7.2 and earlier) to require email verification for strangers.
Liferay Portal / Liferay DXP company.security.strangers.verify = true
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33949?
The severity of CVE-2023-33949 is high.
How does CVE-2023-33949 affect Liferay Portal and Liferay DXP?
CVE-2023-33949 affects Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier.
What is the vulnerability in CVE-2023-33949?
The vulnerability in CVE-2023-33949 is that the default configuration of Liferay Portal and Liferay DXP does not require users to verify their email address.
What can attackers do in CVE-2023-33949?
Attackers can create accounts using fake email addresses or email addresses they don't control in CVE-2023-33949.
How can I fix CVE-2023-33949?
To fix CVE-2023-33949, update Liferay Portal to version 7.3.1 or later, and Liferay DXP to version 7.2.1 or later.