Логотип exploitDog
bind:CVE-2023-33947
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-33947

Количество 2

Количество 2

nvd логотип

CVE-2023-33947

больше 2 лет назад

The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object definition.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-769c-p92r-xgxj

больше 2 лет назад

Liferay portal has unauthorized access to object definition via search

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-33947

The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object definition.

CVSS3: 2.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-769c-p92r-xgxj

Liferay portal has unauthorized access to object definition via search

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу