René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

240 lines
8.7 KiB
JSON

{
"id": "CVE-2021-33324",
"sourceIdentifier": "cve@mitre.org",
"published": "2021-08-03T19:15:08.690",
"lastModified": "2021-08-11T14:49:04.460",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration."
},
{
"lang": "es",
"value": "El m\u00f3dulo Layout en Liferay Portal versiones 7.1.0 hasta 7.3.1, y Liferay DXP versiones 7.1 anterior a fix pack 20, y versiones 7.2 anterior a fix pack 5, no comprueba apropiadamente los permisos de las p\u00e1ginas, que permite a usuarios autenticados remotos sin permiso de visualizaci\u00f3n de una p\u00e1gina visualizar la p\u00e1gina por medio de la administraci\u00f3n de p\u00e1ginas de un sitio"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-276"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:-:*:*:*:*:*:*",
"matchCriteriaId": "C2AA7E18-A41B-4F0D-A04F-57C5745D091B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_1:*:*:*:*:*:*",
"matchCriteriaId": "392B783D-620D-4C71-AAA0-848B16964A27"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_10:*:*:*:*:*:*",
"matchCriteriaId": "4F5A94E2-22B7-4D2D-A491-29F395E727C5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_11:*:*:*:*:*:*",
"matchCriteriaId": "E9B10908-C42B-4763-9D47-236506B0E84A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_12:*:*:*:*:*:*",
"matchCriteriaId": "CF544435-36AC-49B8-BA50-A6B6D1678BBC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_13:*:*:*:*:*:*",
"matchCriteriaId": "9D265542-5333-4CCD-90E5-B5F6A55F9863"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_14:*:*:*:*:*:*",
"matchCriteriaId": "1763CD8B-3ACD-4617-A1CA-B9F77A074977"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_15:*:*:*:*:*:*",
"matchCriteriaId": "F25C66AA-B60D-413C-A848-51E12D6080AC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_16:*:*:*:*:*:*",
"matchCriteriaId": "071A0D53-EC95-4B18-9FA3-55208B1F7B94"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_17:*:*:*:*:*:*",
"matchCriteriaId": "CC26A9D4-14D6-46B1-BB00-A2C4386EBCA4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_18:*:*:*:*:*:*",
"matchCriteriaId": "350CDEDA-9A20-4BC3-BEAE-8346CED10CD6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_19:*:*:*:*:*:*",
"matchCriteriaId": "10C6107E-79B3-4672-B3E5-8A2FA9A829CF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_2:*:*:*:*:*:*",
"matchCriteriaId": "3233D306-3F8E-40A4-B132-7264E63DD131"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_3:*:*:*:*:*:*",
"matchCriteriaId": "9EAEA45A-0370-475E-B4CB-395A434DC3A1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_4:*:*:*:*:*:*",
"matchCriteriaId": "39310F05-1DB6-43BA-811C-9CB91D6DCF20"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_5:*:*:*:*:*:*",
"matchCriteriaId": "D6135B16-C89E-4F49-BA15-823E2AF26D68"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_6:*:*:*:*:*:*",
"matchCriteriaId": "CC887BEC-915B-44AC-B473-5448B3D8DCF7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_7:*:*:*:*:*:*",
"matchCriteriaId": "D7A7CC60-C294-41EC-B000-D15AAA93A3D5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_8:*:*:*:*:*:*",
"matchCriteriaId": "022132F8-6E56-4A29-95D6-3B7861D39CDF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.1:fix_pack_9:*:*:*:*:*:*",
"matchCriteriaId": "651DA9B7-9C11-47A7-AF5C-95625C8FFF6A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.2:-:*:*:*:*:*:*",
"matchCriteriaId": "8CAAE1B7-982E-4D50-9651-DEEE6CD74EED"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.2:fix_pack_1:*:*:*:*:*:*",
"matchCriteriaId": "AFCF99EC-3384-418D-A419-B9DB607BE371"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.2:fix_pack_2:*:*:*:*:*:*",
"matchCriteriaId": "31E05134-A0C5-4937-A228-7D0884276B67"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.2:fix_pack_3:*:*:*:*:*:*",
"matchCriteriaId": "3F06C4AD-FD20-4345-8386-0895312F0A00"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:dxp:7.2:fix_pack_4:*:*:*:*:*:*",
"matchCriteriaId": "98CC25E2-EC3D-43A2-8D03-06F0E804EA63"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7.1.0",
"versionEndExcluding": "7.3.2",
"matchCriteriaId": "81929C82-CE15-45AC-94D6-7B6906C9112E"
}
]
}
]
}
],
"references": [
{
"url": "https://issues.liferay.com/browse/LPE-17001",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120747063",
"source": "cve@mitre.org",
"tags": [
"Release Notes",
"Vendor Advisory"
]
}
]
}