Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpgh-6v9w-vfv6

Опубликовано: 20 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict membership of a child site when the "Limit membership to members of the parent site" option is enabled, which allows remote authenticated users to add users who are not a member of the parent site to a child site. The added user may obtain permission to perform unauthorized actions in the child site.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

>= 7.2.0, < 7.4.2-ga3

7.4.2-ga3

Наименование

com.liferay.portal:release.dxp.bom

maven
Затронутые версииВерсия исправления

< 7.2.10.fp15

7.2.10.fp15

EPSS

Процентиль: 49%
0.00259
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict membership of a child site when the "Limit membership to members of the parent site" option is enabled, which allows remote authenticated users to add users who are not a member of the parent site to a child site. The added user may obtain permission to perform unauthorized actions in the child site.

EPSS

Процентиль: 49%
0.00259
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-863