Loading HuntDB...

GHSA-2mx7-xvfg-fg53

GitHub Security Advisory

Liferay Portal's account lockout does not invalidate existing user sessions

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.

Affected Packages

Maven com.liferay.portal:release.portal.bom
Affected versions: 7.2.0 (fixed in 7.3.1)
Maven com.liferay.portal:release.dxp.bom
Affected versions: 7.2.0 (fixed in 7.2.10.fp5)

Related CVEs

Key Information

GHSA ID
GHSA-2mx7-xvfg-fg53
Published
February 8, 2024 3:32 AM
Last Modified
October 3, 2024 6:41 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
com.liferay.portal:release.portal.bom
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.