VYPR
Medium severity5.3NVD Advisory· Published Oct 7, 2022· Updated Jun 17, 2026

CVE-2022-41414

CVE-2022-41414

Description

An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.liferay.portal:release.portal.bomMaven
>= 7.0.0-a1, < 7.4.2-ga37.4.2-ga3
com.liferay.portal:com.liferay.portal.implMaven
< 8.0.08.0.0

Affected products

4

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.