Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43xf-59vr-g4f2

Опубликовано: 15 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Liferay Portal Uses Default Password

Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has changed their initial password, which allows remote users to access and edit content via the API.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

>= 7.4.0, < 7.4.3.112

7.4.3.112

EPSS

Процентиль: 17%
0.00054
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-1393

Связанные уязвимости

CVSS3: 6.5
nvd
5 месяцев назад

Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has changed their initial password, which allows remote users to access and edit content via the API.

EPSS

Процентиль: 17%
0.00054
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-1393