Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4f7-gj7q-xg9m

Опубликовано: 14 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 4.8

Описание

Liferay has Incorrect Permission Assignment for Critical Resource

Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensitive information being exposed to unauthorized users.

Пакеты

Наименование

com.liferay:com.liferay.site.navigation.menu.item.asset.vocabulary

maven
Затронутые версииВерсия исправления

< 1.0.23

1.0.23

EPSS

Процентиль: 12%
0.00041
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensitive information being exposed to unauthorized users.

EPSS

Процентиль: 12%
0.00041
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-732