CVE-2021-33330Resource Exposure in Portal

CWE-668Resource Exposure4 documents4 sources
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 56.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 3
Latest updateMay 24

Description

Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the targeted user’s email address and current CSRF token.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
OSV
Exposure of Resource to Wrong Sphere in Liferay Portal2022-05-24
GHSA
Exposure of Resource to Wrong Sphere in Liferay Portal2022-05-24
CVEList
CVE-2021-33330: Liferay Portal 72021-08-03
CVE-2021-33330 — Resource Exposure in Liferay Portal | cvebase