Headline
CVE-2023-3426: CVE-2023-3426 Unauthorized view access to Organization names - Liferay
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
This website uses cookies to ensure you get the best experience. Learn More.
Accept
- Ask
- Blogs
- Chat
- Download
- Feedback
- Help
- Learn
- Projects
- /dev/24
- Log In
Known Vulnerabilities
- Overview
- Reporting Security Issues
- Known Vulnerabilities
- Hall of Fame
Releases
Liferay Portal 7.4
Liferay Portal 7.3
Liferay Portal 7.2
Liferay Portal 7.1
Liferay Portal 7.0
Liferay Portal 6.2 CE
Liferay Faces
Liferay DXP 7.4
Liferay DXP 7.3
Liferay DXP 7.2
LIferay DXP 7.1
LIferay DXP 7.0
CVE-2023-3426 Unauthorized view access to Organization names
Description
The organization selector in Liferay Portal and Liferay DXP does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
Severity
4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Affected Version(s)
- Liferay DXP 7.4 update 81 through 85
- Liferay Portal 7.4.3.81 - 7.4.3.85
Fixed Version(s)
- Liferay DXP 7.4 update 86
- Liferay Portal 7.4.3.86
Acknowledgments
This issue was reported by 4rth4s
Publication date: Wed, 02 Aug 2023 09:05:00 +0000
Security advisories for Liferay’s enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.