CVE-2022-42132

MEDIUM5.9EPSS 0.33%

Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL

發布日:2022/11/15修改日:2025/7/16

描述

The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.

受影響套件(4)

  • Bitnami/liferay>= 7.0.0, <= 7.0.0, >= 7.1.0, <= 7.1.0, >= 7.2.0, <= 7.2.0, >= 7.3.0, <= 7.3.0, >= 7.4.0, <= 7.4.0 | >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.0-fix.0, <= 7.0-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-fix.0, <= 7.1-fix.0, >= 7.1-sp1.0, <= 7.1-sp1.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.2-fix.0, <= 7.2-fix.0, >= 7.3-fix.0, <= 7.3-fix.0, >= 7.3-fix.0, <= 7.3-fix.0
  • Maven/com.liferay:com.liferay.portal.settings.authentication.ldap.webfrom 0, < 5.0.13
  • Maven/com.liferay.portal:release.dxp.bom>= 7.0.0, <= 7.0.10.fp102
  • Maven/com.liferay.portal:release.portal.bom>= 7.0.0, < 7.4.3.5-ga5

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(9)