Lucene search

K
githubGitHub Advisory DatabaseGHSA-WGQM-QP44-CG6X
HistoryNov 15, 2022 - 12:00 p.m.

Incorrect Default Permissions in Liferay Portal

2022-11-1512:00:16
CWE-276
GitHub Advisory Database
github.com
9
liferay portal
hypermedia
rest apis
vulnerability
default permissions
wikinode

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.002 Low

EPSS

Percentile

56.5%

The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.

Affected configurations

Vulners
Node
com.liferay.portal\Matchrelease.portal.bom

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.002 Low

EPSS

Percentile

56.5%

Related for GHSA-WGQM-QP44-CG6X