PT-2021-20115 · Liferay · Liferay Portal+1

Published

2021-08-03

·

Updated

2022-05-24

·

CVE-2021-33334

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.0.0 through 7.3.2 Liferay DXP 7.0 before fix pack 94 Liferay DXP 7.1 before fix pack 19 Liferay DXP 7.2 before fix pack 6
Description The Dynamic Data Mapping module does not properly check user permissions, allowing remote attackers with the forms "Access in Site Administration" permission to view all forms and form entries in a site via the forms section in site administration.
Recommendations For Liferay Portal versions 7.0.0 through 7.3.2, update to a version that includes the fix for this issue. For Liferay DXP 7.0, apply fix pack 94 or later. For Liferay DXP 7.1, apply fix pack 19 or later. For Liferay DXP 7.2, apply fix pack 6 or later. As a temporary workaround, consider restricting access to the forms section in site administration to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33334
GHSA-G37F-J8HH-736F

Affected Products

Liferay Dxp
Liferay Portal