Security LDAP Implementation before 2.0.16 from Liferay Portal through v7.2.1 and Liferay DXP through v7.2 does not correctly import users from LDAP, allowing remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exists in LDAP.
{ "github_reviewed": true, "cwe_ids": [], "nvd_published_at": "2022-03-02T23:15:00Z", "severity": "HIGH", "github_reviewed_at": "2025-07-14T20:52:18Z" }