Liferay Portal and Liferay DXP fails to properly import users from LDAP
High severity
GitHub Reviewed
Published
Mar 4, 2022
to the GitHub Advisory Database
•
Updated Jul 14, 2025
Description
Published by the National Vulnerability Database
Mar 2, 2022
Published to the GitHub Advisory Database
Mar 4, 2022
Reviewed
Jul 14, 2025
Last updated
Jul 14, 2025
Security LDAP Implementation before 2.0.16 from Liferay Portal through v7.2.1 and Liferay DXP through v7.2 does not correctly import users from LDAP, allowing remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exists in LDAP.
References