QID 731011

Date Published: 2023-12-26

QID 731011: Liferay Portal Unauthorized Access Vulnerability

The Object module in Liferay Portal does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object definition.
Affected Versions:
Liferay Portal 7.4.3.4 - 7.4.3.60
QID Detection Logic (Unauthenticated):

This QID checks for vulnerable version of Liferay Portal in response banner.

Successful exploit may allow remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object definition.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution

    Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory

    CVEs related to QID 731011

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-33947 URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33947