CVE Vulnerabilities

CVE-2020-13444

Published: Jun 10, 2020 | Modified: Jul 16, 2020
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.

Affected Software

Name Vendor Start Version End Version
Liferay_portal Liferay 7.1-ga1 (including) 7.1-ga1 (including)
Liferay_portal Liferay 7.1-ga2 (including) 7.1-ga2 (including)
Liferay_portal Liferay 7.1-ga3 (including) 7.1-ga3 (including)
Liferay_portal Liferay 7.1.1-ga2 (including) 7.1.1-ga2 (including)
Liferay_portal Liferay 7.2-ga1 (including) 7.2-ga1 (including)
Liferay_portal Liferay 7.3-ga1 (including) 7.3-ga1 (including)
Liferay_portal Liferay 7.3-ga2 (including) 7.3-ga2 (including)

References