PT-2023-24588 · Liferay · Liferay Dxp+1
CVE-2023-33946
·
Published
2023-05-24
·
Updated
2024-01-31
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Liferay Portal versions 7.4.3.4 through 7.4.3.48
Liferay DXP 7.4 before update 49
Description
The issue allows remote authenticated users in one virtual instance to view objects in a different virtual instance via the OAuth 2 scope administration page, due to the Object module not properly isolating objects in different virtual instances.
Recommendations
For Liferay Portal versions 7.4.3.4 through 7.4.3.48, update to a version after 7.4.3.48 to resolve the issue.
For Liferay DXP 7.4 before update 49, apply update 49 or later to fix the problem.
As a temporary workaround, consider restricting access to the OAuth 2 scope administration page to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liferay Dxp
Liferay Portal