Description
Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated attackers to prevent any user from authenticating by (1) enabling Time-based One-time password (TOTP) on behalf of the other user or (2) modifying the other user's TOTP shared secret.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15687 | Liferay DXP Vulnerable to Denial-of-service (DoS) in the Multi-Factor Authentication Module |
Github GHSA |
GHSA-82j7-2h3j-hc7f | Liferay DXP Vulnerable to Denial-of-service (DoS) in the Multi-Factor Authentication Module |
References
| Link | Providers |
|---|---|
| http://liferay.com |
|
| https://issues.liferay.com/browse/LPE-17131 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T21:55:12.504Z
Reserved: 2021-03-22T00:00:00.000Z
Link: CVE-2021-29041
No data.
Status : Modified
Published: 2021-05-16T16:15:07.260
Modified: 2024-11-21T06:00:34.730
Link: CVE-2021-29041
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA