CVE-2021-29052Incorrect Default Permissions in Portal

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 71.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateMay 24

Description

The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey, which allows remote authenticated users to view DDMStructures via GET API calls.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDliferay/liferay_portal7.3.07.3.5
NVDliferay/dxp7.3

🔴Vulnerability Details

3
OSV
Liferay Portal and Liferay DXP Fails to Check Permissions2022-05-24
GHSA
Liferay Portal and Liferay DXP Fails to Check Permissions2022-05-24
CVEList
CVE-2021-29052: The Data Engine module in Liferay Portal 72021-05-17
CVE-2021-29052 — Incorrect Default Permissions | cvebase