Workflow Context saves sensitive information

7.0 Fix Pack Version

93

7.1 Fix Pack Version

19

7.2 Fix Pack Version

7

7.3 Fix Pack Version

None

7.4 Fix Pack Version

None

CVE IDs

CVSS Base Score

CVSS Vector String

Description

In Liferay DXP 7.0, 7.1 and 7.2, user's passwords are stored in the database if workflow is enabled for new users. This allows attackers with access to the database to obtain the user's unencrypted password.

Activity

Show:
Fixed
Pinned fields
Click on the next to a field label to start pinning.

Details

Assignee

Reporter

Priority

Components

Zendesk Support

Created June 12, 2020 at 1:18 AM
Updated August 2, 2021 at 12:04 AM
Resolved August 3, 2020 at 3:22 AM