Liferay DXP Vulnerable to Denial-of-service (DoS) in the Multi-Factor Authentication Module
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 14, 2025
Package
Affected versions
< 7.3.10.fp1
Patched versions
7.3.10.fp1
Description
Published by the National Vulnerability Database
May 16, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
May 14, 2025
Last updated
May 14, 2025
Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated attackers to prevent any user from authenticating by (1) enabling Time-based One-time password (TOTP) on behalf of the other user or (2) modifying the other user's TOTP shared secret.
References