Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40833
HistoryJun 08, 2023 - 8:59 a.m.

Information Disclosure

2023-06-0808:59:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
information disclosure
remote attacker
object module
virtual instance
sensitive information

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

30.0%

com.liferay.portal:com.liferay.portal.kernel is vulnerable to Information Disclosure. A remote authorized attacker is able to view the object definition from a second virtual instance because the Object module does not segment object definition by virtual instance in search, resulting in the disclosure of sensitive information.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

30.0%