Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-33946
HistoryMay 24, 2023 - 4:15 p.m.

Design/Logic Flaw

2023-05-2416:15:00
PRIOn knowledge base
www.prio-n.com
5
design/logic flaw
object module
liferay portal
remote authenticated users
virtual instances
oauth 2

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.0%

The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page.

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.0%

Related for PRION:CVE-2023-33946