Unauthorized Access Vulnerability in Liferay Portal and DXP by Liferay
CVE-2022-26595
4.3MEDIUM
Key Information:
- Vendor
Liferay
- Vendor
- CVE Published:
- 19 April 2022
What is CVE-2022-26595?
An authorization bypass vulnerability exists in Liferay Portal and DXP, specifically in versions 7.3.7, 7.4.0, 7.4.1, and their respective DXP fix packs. This flaw permits authenticated users to access and view sensitive information about sites and groups, which they should not have permission to see, through the user interface that displays site membership assignments. This could lead to unintended exposure of information, potentially affecting the confidentiality and integrity of site data.