Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv7w-jh8g-vr73

Опубликовано: 28 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Liferay Portal Does Not Limit Access to APIs Before Email Verification

Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

>= 7.4.0-ga1, < 7.4.3.110

7.4.3.110

EPSS

Процентиль: 17%
0.00054
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.4
nvd
3 месяца назад

Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API.

EPSS

Процентиль: 17%
0.00054
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-863