"-Synchronized-Data."

This commit is contained in:
CVE Team 2020-07-16 14:01:22 +00:00
parent 6ec09f3328
commit 66169ad589
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743
2 changed files with 11 additions and 1 deletions

View File

@ -34,7 +34,7 @@
"description_data": [
{
"lang": "eng",
"value": "Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 19, and 7.2 before fix pack 7, does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers."
"value": "Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers."
}
]
},
@ -56,6 +56,11 @@
"refsource": "CONFIRM",
"name": "https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119317396",
"url": "https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119317396"
},
{
"refsource": "CONFIRM",
"name": "https://issues.liferay.com/browse/LPE-17009",
"url": "https://issues.liferay.com/browse/LPE-17009"
}
]
}

View File

@ -106,6 +106,11 @@
"refsource": "MISC",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-364335.pdf",
"name": "https://cert-portal.siemens.com/productcert/pdf/ssa-364335.pdf"
},
{
"refsource": "MISC",
"name": "https://us-cert.cisa.gov/ics/advisories/icsa-20-196-04",
"url": "https://us-cert.cisa.gov/ics/advisories/icsa-20-196-04"
}
]
}