com.liferay:com.liferay.portal.security.ldap.impl@1.0.42 vulnerabilities
-
latest version
4.0.61
-
latest non vulnerable version
-
first published
6 years ago
-
latest version published
2 months ago
-
licenses detected
- [1.0.0,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the com.liferay:com.liferay.portal.security.ldap.impl package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Improper Authentication which incorrectly import users from LDAP, allowing remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exists in LDAP. How to fix Improper Authentication? Upgrade |
[,2.0.16)
|