Description
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.
References
Vendor Advisory
https://issues.liferay.com/browse/LPE-17593
Vendor Advisory
Vendor Advisory
https://issues.liferay.com/browse/LPE-17593
Vendor Advisory
Weaknesses
Primary
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-284
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
4.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-15T00:15:13.267Z
3 years agoLast modified
2025-04-30T13:15:56.240Z
11 months ago