CVE-2021-33323: High severity liferay 7.4 ga vulnerability
The Dynamic Data Mapping module in Dynamic Data Mapping Form Web before 3.0.23 in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.
Other sources
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2021-33323.
What is the severity of CVE-2021-33323?
The severity of CVE-2021-33323 is high (7.5).
Which versions of Liferay Portal and Liferay DXP are affected by CVE-2021-33323?
CVE-2021-33323 affects Liferay Portal versions 7.1.0 through 7.3.2 and Liferay DXP versions 7.1 before fix pack 19 and 7.2 before fix pack 7.
What is the impact of CVE-2021-33323?
CVE-2021-33323 allows remote attackers to view the autosaved form values for unauthenticated users in Liferay Portal and Liferay DXP.
How can I fix CVE-2021-33323?
To fix CVE-2021-33323, you should apply the relevant fix pack for your affected Liferay Portal or Liferay DXP version.