CVE Vulnerabilities

CVE-2021-33323

Cleartext Storage of Sensitive Information

Published: Aug 03, 2021 | Modified: May 13, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

NameVendorStart VersionEnd Version
Digital_experience_platformLiferay7.1 (including)7.1 (including)
Digital_experience_platformLiferay7.1-fix_pack_1 (including)7.1-fix_pack_1 (including)
Digital_experience_platformLiferay7.1-fix_pack_10 (including)7.1-fix_pack_10 (including)
Digital_experience_platformLiferay7.1-fix_pack_11 (including)7.1-fix_pack_11 (including)
Digital_experience_platformLiferay7.1-fix_pack_12 (including)7.1-fix_pack_12 (including)
Digital_experience_platformLiferay7.1-fix_pack_13 (including)7.1-fix_pack_13 (including)
Digital_experience_platformLiferay7.1-fix_pack_14 (including)7.1-fix_pack_14 (including)
Digital_experience_platformLiferay7.1-fix_pack_15 (including)7.1-fix_pack_15 (including)
Digital_experience_platformLiferay7.1-fix_pack_16 (including)7.1-fix_pack_16 (including)
Digital_experience_platformLiferay7.1-fix_pack_17 (including)7.1-fix_pack_17 (including)
Digital_experience_platformLiferay7.1-fix_pack_18 (including)7.1-fix_pack_18 (including)
Digital_experience_platformLiferay7.1-fix_pack_2 (including)7.1-fix_pack_2 (including)
Digital_experience_platformLiferay7.1-fix_pack_3 (including)7.1-fix_pack_3 (including)
Digital_experience_platformLiferay7.1-fix_pack_4 (including)7.1-fix_pack_4 (including)
Digital_experience_platformLiferay7.1-fix_pack_5 (including)7.1-fix_pack_5 (including)
Digital_experience_platformLiferay7.1-fix_pack_6 (including)7.1-fix_pack_6 (including)
Digital_experience_platformLiferay7.1-fix_pack_7 (including)7.1-fix_pack_7 (including)
Digital_experience_platformLiferay7.1-fix_pack_8 (including)7.1-fix_pack_8 (including)
Digital_experience_platformLiferay7.1-fix_pack_9 (including)7.1-fix_pack_9 (including)
Digital_experience_platformLiferay7.2 (including)7.2 (including)
Digital_experience_platformLiferay7.2-fix_pack_1 (including)7.2-fix_pack_1 (including)
Digital_experience_platformLiferay7.2-fix_pack_2 (including)7.2-fix_pack_2 (including)
Digital_experience_platformLiferay7.2-fix_pack_3 (including)7.2-fix_pack_3 (including)
Digital_experience_platformLiferay7.2-fix_pack_4 (including)7.2-fix_pack_4 (including)
Digital_experience_platformLiferay7.2-fix_pack_5 (including)7.2-fix_pack_5 (including)
Digital_experience_platformLiferay7.2-fix_pack_6 (including)7.2-fix_pack_6 (including)
Liferay_portalLiferay7.1.0 (including)7.3.1 (excluding)

Potential Mitigations

References