Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xxc-4jc4-7jv3

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Exposure of Resource to Wrong Sphere in Liferay Portal

Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the targeted user’s email address and current CSRF token.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

>= 7.2.0, < 7.3.3

7.3.3

EPSS

Процентиль: 43%
0.00207
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the targeted user’s email address and current CSRF token.

EPSS

Процентиль: 43%
0.00207
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668