Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j82q-c85j-xw4w

Опубликовано: 23 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Liferay Portal and DXP do not properly restrict access to OpenAPI

Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.

Пакеты

Наименование

com.liferay:com.liferay.portal.security.auth.verifier

maven
Затронутые версииВерсия исправления

< 6.0.26

6.0.26

EPSS

Процентиль: 4%
0.00018
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
4 месяца назад

Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.

EPSS

Процентиль: 4%
0.00018
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-862