CVE Vulnerabilities

CVE-2023-3426

Direct Request ('Forced Browsing')

Published: Aug 02, 2023 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
Digital_experience_platformLiferay7.4-update81 (including)7.4-update81 (including)
Digital_experience_platformLiferay7.4-update82 (including)7.4-update82 (including)
Digital_experience_platformLiferay7.4-update83 (including)7.4-update83 (including)
Digital_experience_platformLiferay7.4-update84 (including)7.4-update84 (including)
Digital_experience_platformLiferay7.4-update85 (including)7.4-update85 (including)
Liferay_portalLiferay7.4.3.81 (including)7.4.3.85 (including)

Potential Mitigations

References