Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5x9h-p2gx-35mg

Опубликовано: 15 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Incorrect Default Permissions in Liferay Portal

The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

>= 7.4.3.5, <= 7.4.3.36

7.4.3.48

EPSS

Процентиль: 40%
0.00186
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.

EPSS

Процентиль: 40%
0.00186
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-276