Lucene search

K
osvGoogleOSV:BIT-LIFERAY-2022-42128
HistoryJan 31, 2024 - 3:20 p.m.

BIT-liferay-2022-42128

2024-01-3115:20:01
Google
osv.dev
5
hypermedia
rest apis
liferay portal
liferay dxp
permission
vulnerability
wikinoderesource
api

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

6.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.5%

The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.

CPENameOperatorVersion
liferayge7.4.0
liferayle7.4.0

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

6.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.5%

Related for OSV:BIT-LIFERAY-2022-42128