Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the users site membership assignment UI.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Digital_experience_platform | Liferay | 7.2-fix_pack_13 (including) | 7.2-fix_pack_13 (including) |
Digital_experience_platform | Liferay | 7.3-fix_pack_2 (including) | 7.3-fix_pack_2 (including) |
Liferay_portal | Liferay | 7.3.7 (including) | 7.3.7 (including) |
Liferay_portal | Liferay | 7.4.0 (including) | 7.4.0 (including) |
Liferay_portal | Liferay | 7.4.1 (including) | 7.4.1 (including) |