Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqwv-9xh5-25fg

Опубликовано: 22 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 2

Описание

Liferay Portal and DXP are Missing Authorization in Collection Provider

Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows instance users to read and select unauthorized Blueprints through the Collection Providers across instances.

Пакеты

Наименование

com.liferay:com.liferay.search.experiences.service

maven
Затронутые версииВерсия исправления

<= 3.0.84

Отсутствует

EPSS

Процентиль: 13%
0.00044
Низкий

2 Low

CVSS4

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows instance users to read and select unauthorized Blueprints through the Collection Providers across instances.

EPSS

Процентиль: 13%
0.00044
Низкий

2 Low

CVSS4

Дефекты

CWE-862