CVE-2023-47798: Medium severity liferay 7.4 ga vulnerability
Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47798?
CVE-2023-47798 is considered a high severity vulnerability due to the risk of user sessions remaining authenticated even after an account is locked.
How do I fix CVE-2023-47798?
To resolve CVE-2023-47798, upgrade to Liferay Portal 7.2.10 fix pack 5 or Liferay DXP 7.3.1 or higher.
Who is affected by CVE-2023-47798?
CVE-2023-47798 affects users of Liferay Portal versions 7.2.0 to 7.3.0 and earlier unsupported versions.
What is the impact of CVE-2023-47798?
CVE-2023-47798 allows remote authenticated users to maintain access after their accounts have been locked, posing a security risk.
Is there a workaround for CVE-2023-47798?
There are no specific known workarounds for CVE-2023-47798; upgrading to a fixed version is recommended.