Excessive privileges In com.liferay.portal:release.portal.bom
Description
Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 7.3.5 | ||
maven | 7.1.10.fp20, 7.2.10.fp9 |
Aliases
1. 2. 3. 4.
References
1. 2.