CVE-2022-39975 – com.liferay.portal:release.portal.bom
Package
Manager: maven
Name: com.liferay.portal:release.portal.bom
Vulnerable Version: >=7.3.3 <7.4.3.35
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00201 pctl0.42315
Details
Liferay Portal Missing Authorization vulnerability The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
Metadata
Created: 2022-09-23T00:00:46Z
Modified: 2022-09-23T21:00:25Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-83qx-288m-72w4/GHSA-83qx-288m-72w4.json
CWE IDs: ["CWE-862"]
Alternative ID: GHSA-83qx-288m-72w4
Finding: F039
Auto approve: 1