High severity7.5NVD Advisory· Published Aug 3, 2021· Updated Jun 17, 2026
CVE-2021-33321
CVE-2021-33321
Description
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.password should be defaulted to true.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay.portal:com.liferay.portal.implMaven | < 5.11.0 | 5.11.0 |
com.liferay.portal:release.portal.bomMaven | < 7.3.3 | 7.3.3 |
Affected products
5- ghsa-coords2 versions
< 5.11.0+ 1 more
- (no CPE)range: < 5.11.0
- (no CPE)range: < 7.3.3
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-jfch-m2x3-2v66ghsaADVISORY
- help.liferay.com/hc/en-us/articles/360050785632nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-33321ghsaADVISORY
- portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120748055nvdRelease NotesVendor AdvisoryWEB
- github.com/liferay/liferay-portal/commit/06df28c5ad618afed967fa485418e6cc29c70f38ghsaWEB
- github.com/liferay/liferay-portal/commit/37de1d78d9b1c4a473e3233a6ea146c741075e18ghsaWEB
News mentions
0No linked articles in our index yet.