Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf7m-v66q-76w8

Опубликовано: 01 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Liferay Portal and DXP do not check permissions of images in a blog entry

Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to view the images in a blog entry via crafted URL.

Пакеты

Наименование

com.liferay:com.liferay.blogs.item.selector.web

maven
Затронутые версииВерсия исправления

< 6.0.19

6.0.19

EPSS

Процентиль: 18%
0.00057
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to view the images in a blog entry via crafted URL.

EPSS

Процентиль: 18%
0.00057
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-863