Insecure Default Initialization In Liferay Portal
Moderate severity
GitHub Reviewed
Published
May 24, 2023
to the GitHub Advisory Database
•
Updated Nov 6, 2023
Package
Affected versions
>= 7.0.0, < 7.3.1
Patched versions
7.3.1
Description
Published by the National Vulnerability Database
May 24, 2023
Published to the GitHub Advisory Database
May 24, 2023
Reviewed
May 24, 2023
Last updated
Nov 6, 2023
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property
company.security.strangers.verify
should be set to true.References