Home
MEDIUM: 6.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:NDefault status
unaffected
7.4.0 (maven)
affected
Default status
unaffected
7.4.13 (maven)
affected
2024.Q1.1 (maven)
affected
2024.Q2.0 (maven)
affected
Description
Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entries information via the API Builder.
Problem types
CWE-863: Incorrect Authorization
Product status
7.4.0 (maven)
7.4.13 (maven)
2024.Q1.1 (maven)
2024.Q2.0 (maven)
References
liferay.dev/...-/asset_publisher/jekt/content/CVE-2025-43784