Uploaded image for project: 'PUBLIC - Liferay Portal Enterprise Edition'
  1. PUBLIC - Liferay Portal Enterprise Edition
  2. LPE-1453

IFrame portlet vulnerable to password theft

Details

    Description

      The IFrame portlet is vulnerable to password theft if untrusted users are allowed to add an IFrame portlet to a page. The untrusted user can configured the portlet to use the token @[email protected] (which contains a user's portal password) to send a user's password to a page that is setup to record the passwords.

      To address this issue, a new property has been added to portal(-ext).properties

      #

      1. Specify a role name that a user must be associated with in order to
      2. configure the IFrame portlet to use the @[email protected] token. This token is
      3. used to post the password of users who access this portlet in order to
      4. automatically login to the framed site.
        #
      5. No role is required by default. However, it is recommended that you
      6. specify a role in high security environments where users who configure
      7. this portlet may attempt password theft.
        #
        iframe.password.token.role

      Attachments

        Issue Links

          Activity

            People

              michael.saechang Michael Saechang
              brian.chan Brian Chan
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Packages

                  Version Package
                  5.1 EE SP5 (5.1.8)
                  5.2 EE SP2 (5.2.6)