CVE-2023-47798

Session Fixation in maven/com.liferay.portal/release.dxp.bom

Identifiers

GHSA-2mx7-xvfg-fg53, CVE-2023-47798

Package Slug

maven/com.liferay.portal/release.dxp.bom

Vulnerability

Session Fixation

Description

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.

Affected Versions

All versions starting from 7.2.0 before 7.2.10.fp5

Solution

Upgrade to version 7.2.10.fp5 or above.

Last Modified

2024-02-19

source