CST-7136 OpenID phishing attack vulnerability

Description

In Liferay Portal 7.1 CE GA4 and possibly earlier unsupported versions, users may be tricked into creating an account with an OpenID provider. If the OpenID provider is not trustworthy, an attacker can obtain the user's password and access the user's account.

Severity

Severity 2

Fixed Version(s)

Publication date: Tue, 25 Jun 2019 22:36:00 +0000