Описание
Incorrect Default Permissions in Liferay Portal
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.
Пакеты
Наименование
com.liferay.portal:release.portal.bom
maven
Затронутые версииВерсия исправления
>= 7.4.1, <= 7.4.3.4
7.4.3.5
Связанные уязвимости
CVSS3: 5.3
nvd
около 3 лет назад
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.