com.liferay:com.liferay.portal.settings.authentication.ldap.web@3.0.29 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the com.liferay:com.liferay.portal.settings.authentication.ldap.web package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Information Exposure

com.liferay:com.liferay.portal.settings.authentication.ldap.web is a settings authentication module for LifeRay.

Affected versions of this package are vulnerable to Information Exposure such that the Test LDAP Users functionality includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.

How to fix Information Exposure?

Upgrade com.liferay:com.liferay.portal.settings.authentication.ldap.web to version 5.0.13 or higher.

[,5.0.13)