GHSA-g9mr-9xfc-4gf7

Suggest an improvement
Source
https://github.com/advisories/GHSA-g9mr-9xfc-4gf7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-g9mr-9xfc-4gf7/GHSA-g9mr-9xfc-4gf7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g9mr-9xfc-4gf7
Aliases
Published
2023-05-24T18:30:26Z
Modified
2024-02-16T08:12:53.840916Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Insecure Default Initialization In Liferay Portal
Details

In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property company.security.strangers.verify should be set to true.

Database specific
{
    "nvd_published_at": "2023-05-24T17:15:09Z",
    "cwe_ids": [
        "CWE-1188"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-05-24T21:53:45Z"
}
References

Affected packages

Maven / com.liferay.portal:release.portal.bom

Package

Name
com.liferay.portal:release.portal.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.portal.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.3.1

Affected versions

7.*

7.0.6
7.0.6-1
7.0.6-2
7.1.0
7.1.1
7.1.2
7.1.3
7.1.3-1
7.2.0
7.2.1
7.2.1-1
7.3.0
7.3.0-1