CVE-2023-47798

Session Fixation in maven/com.liferay.portal/release.portal.bom

Identifiers

GHSA-2mx7-xvfg-fg53, CVE-2023-47798

Package Slug

maven/com.liferay.portal/release.portal.bom

Vulnerability

Session Fixation

Description

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.

Affected Versions

All versions starting from 7.2.0 before 7.3.1

Solution

Upgrade to version 7.3.1 or above.

Last Modified

2024-02-19

source