CVE-2021-29052: Medium severity Liferay DXP vulnerability
The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey, which allows remote authenticated users to view DDMStructures via GET API calls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.fp1 - Upgrade
Upgrade
Liferay Portal 7.3.0-7.3.5, Liferay DXP 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch fix pack 1 - Compensating control
Restrict access to the Liferay GET APIs that expose DDMStructures/`DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey` to trusted users (e.g., via network ACL/firewall/WAF) until the fix pack is applied.
Event History
Frequently Asked Questions
What is the vulnerability ID for this Liferay Portal and Liferay DXP vulnerability?
The vulnerability ID is CVE-2021-29052.
What is the severity of CVE-2021-29052?
The severity of CVE-2021-29052 is medium.
Which software versions are affected by CVE-2021-29052?
Liferay Portal versions 7.3.0 through 7.3.5, and Liferay DXP version 7.3 before fix pack 1 are affected by CVE-2021-29052.
How can remote authenticated users exploit CVE-2021-29052?
Remote authenticated users can exploit CVE-2021-29052 by making GET API calls to view DDMStructures without proper permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey.
Where can I find more information about CVE-2021-29052?
You can find more information about CVE-2021-29052 on the Liferay website (http://liferay.com) and the Liferay Developer Portal (https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743159).