Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers.
History

Fri, 15 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-640
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-15T18:05:06.484Z

Reserved: 2021-03-22T00:00:00

Link: CVE-2021-29038

cve-icon Vulnrichment

Updated: 2024-08-03T21:55:12.408Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-20T22:15:08.010

Modified: 2024-11-21T06:00:34.147

Link: CVE-2021-29038

cve-icon Redhat

No data.