Количество 2
Количество 2

CVE-2023-33946
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page.
GHSA-2868-ff44-43qv
Liferay portal unauthorized access to objects via OAuth 2 scope
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2023-33946 The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page. | CVSS3: 2.7 | 0% Низкий | около 2 лет назад |
GHSA-2868-ff44-43qv Liferay portal unauthorized access to objects via OAuth 2 scope | CVSS3: 4.3 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу