Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v53g-736w-mgw4

Опубликовано: 12 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Liferay Portal's Organization Selector exposes organization data to remote authenticated users

The Organization Selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

Пакеты

Наименование

com.liferay:com.liferay.organizations.item.selector.web

maven
Затронутые версииВерсия исправления

>= 4.0.2, < 4.0.22

4.0.22

EPSS

Процентиль: 19%
0.00062
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
5 месяцев назад

The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

EPSS

Процентиль: 19%
0.00062
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862