Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-3426: CVE-2023-3426 Unauthorized view access to Organization names - Liferay

The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

CVE
#vulnerability#web#auth

This website uses cookies to ensure you get the best experience. Learn More.

Accept

  • Ask
  • Blogs
  • Chat
  • Download
  • Feedback
  • Help
  • Learn
  • Projects
  • /dev/24
  • Log In

Known Vulnerabilities

  • Overview
  • Reporting Security Issues
  • Known Vulnerabilities
  • Hall of Fame

Releases

  • Liferay Portal 7.4

  • Liferay Portal 7.3

  • Liferay Portal 7.2

  • Liferay Portal 7.1

  • Liferay Portal 7.0

  • Liferay Portal 6.2 CE

  • Liferay Faces

  • Liferay DXP 7.4

  • Liferay DXP 7.3

  • Liferay DXP 7.2

  • LIferay DXP 7.1

  • LIferay DXP 7.0

CVE-2023-3426 Unauthorized view access to Organization names

Description

The organization selector in Liferay Portal and Liferay DXP does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

Severity

4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

Affected Version(s)

  • Liferay DXP 7.4 update 81 through 85
  • Liferay Portal 7.4.3.81 - 7.4.3.85

Fixed Version(s)

  • Liferay DXP 7.4 update 86
  • Liferay Portal 7.4.3.86

Acknowledgments

This issue was reported by 4rth4s

Publication date: Wed, 02 Aug 2023 09:05:00 +0000

Security advisories for Liferay’s enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907