CVE-2021-33327: Medium severity liferay 7.4 ga vulnerability
The Portlet Configuration module before 4.0.13 in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.
Other sources
The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-33327?
CVE-2021-33327 is a vulnerability in the Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3 and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is disabled.
How severe is CVE-2021-33327?
CVE-2021-33327 has a severity score of 4.3, which is considered medium.
Which software versions are affected by CVE-2021-33327?
CVE-2021-33327 affects Liferay Portal versions 7.2.0 through 7.3.3, Liferay DXP versions 7.0 fix pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8.
How can I fix CVE-2021-33327?
To fix CVE-2021-33327, users are advised to apply the necessary patches or updates provided by Liferay for the affected software versions.
Where can I find more information about CVE-2021-33327?
You can find more information about CVE-2021-33327 at the following references: [Link 1](https://issues.liferay.com/browse/LPE-17075), [Link 2](https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120747840)