Skip to main content

Cleartext Storage of Sensitive Information

CVE-2021-33323

Severity High
Score 7.5/10

Summary

The Dynamic Data Mapping module in Liferay Portal 7.1.0 prior to 7.3.3, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-312 - Cleartext Storage of Sensitive Information

The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Advisory Timeline

  • Published