CVE-2021-29052
17.05.2021, 12:15
The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey, which allows remote authenticated users to view DDMStructures via GET API calls.Enginsight
Vendor | Product | Version |
---|---|---|
liferay | dxp | 7.3 |
liferay | liferay_portal | 7.3.0 ≤ 𝑥 ≤ 7.3.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration