logo

CVE-2022-39975 com.liferay.portal:release.portal.bom

Package

Manager: maven
Name: com.liferay.portal:release.portal.bom
Vulnerable Version: >=7.3.3 <7.4.3.35

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00201 pctl0.42315

Details

Liferay Portal Missing Authorization vulnerability The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.

Metadata

Created: 2022-09-23T00:00:46Z
Modified: 2022-09-23T21:00:25Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-83qx-288m-72w4/GHSA-83qx-288m-72w4.json
CWE IDs: ["CWE-862"]
Alternative ID: GHSA-83qx-288m-72w4
Finding: F039
Auto approve: 1