QID 731147
Date Published: 2024-02-12
QID 731147: Liferay Portal Account Lockout Bypass Vulnerability (CVE-2023-47798)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
Account lockout in Liferay Portal does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.
Affected Versions:
Liferay Portal version 7.3.0
Liferay Portal versions 7.2.0 and 7.2.1
Liferay Portal, older unsupported versions
QID Detection Logic (Unauthenticated): This QID checks for vulnerable versions of Liferay Portal in the response banner.
Successful exploitation of this vulnerability allows remote authenticated users to remain authenticated after an account has been locked.
Solution
Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory
Vendor References
CVEs related to QID 731147
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-47798 |
|