Liferay Portal Cleartext Storage of Sensitive Information Vulnerability - CVE-2021-33325
The Portal Workflow module in Liferay Portal 7.3.2 and earlier and Liferay DXP 7.0 before fix pack 93 7.1 before fix pack 19 and 7.2 before fix pack 7 user39s clear text passwords are stored in the database if workflow is enabled for user creation which allows attackers with access to the database to obtain a user39s password.