Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pw86-qvx9-34r7

Опубликовано: 30 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Liferay Portal Vulnerable to IDOR via audit events

Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users to from one virtual instance to view the audit events from a different virtual instance via the _com_liferay_portal_security_audit_web_portlet_AuditPortlet_auditEventId parameter.

Пакеты

Наименование

com.liferay:com.liferay.portal.security.audit.web

maven
Затронутые версииВерсия исправления

>= 5.0.1, < 5.0.33

5.0.33

Наименование

com.liferay:com.liferay.portal.security.audit.storage.service

maven
Затронутые версииВерсия исправления

>= 6.0.4, < 6.0.41

6.0.41

EPSS

Процентиль: 15%
0.00047
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 4.3
nvd
4 месяца назад

Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users to from one virtual instance to view the audit events from a different virtual instance via the _com_liferay_portal_security_audit_web_portlet_AuditPortlet_auditEventId parameter.

EPSS

Процентиль: 15%
0.00047
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-639