Unauthorized Access Vulnerability in Liferay Portal and DXP by Liferay
CVE-2022-26595
4.3MEDIUM
Key Information:
- Vendor
Liferay
- Vendor
- CVE Published:
- 19 April 2022
What is CVE-2022-26595?
An authorization bypass vulnerability exists in Liferay Portal and DXP, specifically in versions 7.3.7, 7.4.0, 7.4.1, and their respective DXP fix packs. This flaw permits authenticated users to access and view sensitive information about sites and groups, which they should not have permission to see, through the user interface that displays site membership assignments. This could lead to unintended exposure of information, potentially affecting the confidentiality and integrity of site data.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved