QID 731012

Date Published: 2023-12-26

QID 731012: Liferay Portal Unauthorized Access Vulnerability

The Object module in Liferay Portal does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page.
Affected Versions:
Liferay Portal 7.4.3.4 - 7.4.3.48 QID Detection Logic (Unauthenticated):

This QID checks for vulnerable version of Liferay Portal in response banner.

Successful exploit may allow remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution

    Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory

    CVEs related to QID 731012

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-33946 URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33946