LDAP User Authentication Bypass in Liferay Portal and DXP
CVE-2021-38266
7.5HIGH
What is CVE-2021-38266?
The Portal Security module in Liferay Portal and Liferay DXP lacks proper handling of user imports from LDAP directories. This flaw permits remote attackers to disrupt the authentication process for legitimate users by attempting to sign in with LDAP user credentials. As a result, attackers can effectively block a user's access, leading to potential downtime and operational interruptions.