Exposure of Resource to Wrong Sphere in Liferay Portal
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Aug 18, 2023
Package
Affected versions
>= 7.2.0, < 7.3.3
Patched versions
7.3.3
Description
Published by the National Vulnerability Database
Aug 3, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Aug 9, 2023
Last updated
Aug 18, 2023
Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the targeted user’s email address and current CSRF token.
References