GHSA-xph3-vjcq-g488
Dashboard / Vulnerabilities / GHSA-xph3-vjcq-g488
GHSA-xph3-vjcq-g488
Summary: Liferay Portal and Liferay DXP Organization Selector Does Not Check User Permissions
Details: The organization selector before 4.0.14 from Liferay Portal (7.4.3.81 through 7.4.3.85), and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-3426, https://github.com/liferay/liferay-portal/commit/b410f40233394d1d3d1076189befd4b33ba9fb47, https://github.com/liferay/liferay-portal, https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-3426
Affected packages
Package
Name: com.liferay:com.liferay.organizations.item.selector.web
Purl: pkg:maven/com.liferay/com.liferay.organizations.item.selector.web
Affected ranges
Type: ECOSYSTEM
Events:
