First published: Tue Feb 20 2024(Updated: )
User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the request's response time.
Credit: security@liferay.com
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay Liferay Portal | >=7.2.0<7.4.3.26 | |
<7.4.27<7.3.8<7.2.20 | ||
Liferay Liferay Portal | <=7.3.7 | |
Liferay Liferay Portal | >=7.4.0<7.4.3.27 | |
Liferay Digital Experience Platform | <7.2 | |
Liferay Digital Experience Platform | =7.2 | |
Liferay Digital Experience Platform | =7.2-fix_pack_1 | |
Liferay Digital Experience Platform | =7.2-fix_pack_10 | |
Liferay Digital Experience Platform | =7.2-fix_pack_11 | |
Liferay Digital Experience Platform | =7.2-fix_pack_12 | |
Liferay Digital Experience Platform | =7.2-fix_pack_13 | |
Liferay Digital Experience Platform | =7.2-fix_pack_14 | |
Liferay Digital Experience Platform | =7.2-fix_pack_15 | |
Liferay Digital Experience Platform | =7.2-fix_pack_16 | |
Liferay Digital Experience Platform | =7.2-fix_pack_17 | |
Liferay Digital Experience Platform | =7.2-fix_pack_18 | |
Liferay Digital Experience Platform | =7.2-fix_pack_19 | |
Liferay Digital Experience Platform | =7.2-fix_pack_2 | |
Liferay Digital Experience Platform | =7.2-fix_pack_3 | |
Liferay Digital Experience Platform | =7.2-fix_pack_4 | |
Liferay Digital Experience Platform | =7.2-fix_pack_5 | |
Liferay Digital Experience Platform | =7.2-fix_pack_6 | |
Liferay Digital Experience Platform | =7.2-fix_pack_7 | |
Liferay Digital Experience Platform | =7.2-fix_pack_8 | |
Liferay Digital Experience Platform | =7.2-fix_pack_9 | |
Liferay Digital Experience Platform | =7.2-service_pack_1 | |
Liferay Digital Experience Platform | =7.2-service_pack_2 | |
Liferay Digital Experience Platform | =7.2-service_pack_3 | |
Liferay Digital Experience Platform | =7.2-service_pack_4 | |
Liferay Digital Experience Platform | =7.2-service_pack_5 | |
Liferay Digital Experience Platform | =7.2-service_pack_6 | |
Liferay Digital Experience Platform | =7.2-service_pack_7 | |
Liferay Digital Experience Platform | =7.3 | |
Liferay Digital Experience Platform | =7.3-fix_pack_1 | |
Liferay Digital Experience Platform | =7.3-fix_pack_2 | |
Liferay Digital Experience Platform | =7.3-service_pack_1 | |
Liferay Digital Experience Platform | =7.3-service_pack_3 | |
Liferay Digital Experience Platform | =7.3-update4 | |
Liferay Digital Experience Platform | =7.3-update5 | |
Liferay Digital Experience Platform | =7.3-update6 | |
Liferay Digital Experience Platform | =7.3-update7 | |
Liferay Digital Experience Platform | =7.4 | |
Liferay Digital Experience Platform | =7.4-update1 | |
Liferay Digital Experience Platform | =7.4-update10 | |
Liferay Digital Experience Platform | =7.4-update11 | |
Liferay Digital Experience Platform | =7.4-update12 | |
Liferay Digital Experience Platform | =7.4-update13 | |
Liferay Digital Experience Platform | =7.4-update14 | |
Liferay Digital Experience Platform | =7.4-update15 | |
Liferay Digital Experience Platform | =7.4-update16 | |
Liferay Digital Experience Platform | =7.4-update17 | |
Liferay Digital Experience Platform | =7.4-update18 | |
Liferay Digital Experience Platform | =7.4-update19 | |
Liferay Digital Experience Platform | =7.4-update2 | |
Liferay Digital Experience Platform | =7.4-update20 | |
Liferay Digital Experience Platform | =7.4-update21 | |
Liferay Digital Experience Platform | =7.4-update22 | |
Liferay Digital Experience Platform | =7.4-update23 | |
Liferay Digital Experience Platform | =7.4-update24 | |
Liferay Digital Experience Platform | =7.4-update25 | |
Liferay Digital Experience Platform | =7.4-update26 | |
Liferay Digital Experience Platform | =7.4-update3 | |
Liferay Digital Experience Platform | =7.4-update4 | |
Liferay Digital Experience Platform | =7.4-update5 | |
Liferay Digital Experience Platform | =7.4-update6 | |
Liferay Digital Experience Platform | =7.4-update7 | |
Liferay Digital Experience Platform | =7.4-update8 | |
Liferay Digital Experience Platform | =7.4-update9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.