CVE-2021-38268: Medium severity Liferay Digital Experience Platform vulnerability
The Dynamic Data Mapping module before 4.0.39 from Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the API.
Other sources
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the API.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.fp2 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp10 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.1.10.fp21 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.0.10.fp101 - Upgrade
Upgrade
maven/com.liferay:com.liferay.dynamic.data.mapping.serviceto a version that resolves this vulnerability.Fixed in 6.0.0 - Upgrade
Upgrade
Liferay Portal Dynamic Data Mapping (DDM)to a version that resolves this vulnerability.Fixed in 4.0.39 - Upgrade
Upgrade
Liferay DXP 7.0to a version that resolves this vulnerability.Patch fix pack 101 - Upgrade
Upgrade
Liferay DXP 7.1to a version that resolves this vulnerability.Patch fix pack 21 - Upgrade
Upgrade
Liferay DXP 7.2to a version that resolves this vulnerability.Patch fix pack 10 - Upgrade
Upgrade
Liferay DXP 7.3to a version that resolves this vulnerability.Patch fix pack 2
Event History
Frequently Asked Questions
What is CVE-2021-38268?
CVE-2021-38268 is a vulnerability in Liferay Portal and Liferay DXP that allows remote authenticated users with site member permissions to add new forms by default.
What is the severity of CVE-2021-38268?
CVE-2021-38268 has a severity level of medium (CVSS score of 6.5).
Which versions of Liferay Portal and Liferay DXP are affected by CVE-2021-38268?
CVE-2021-38268 affects Liferay Portal versions 7.0.0 through 7.3.6, and Liferay DXP versions 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10, and 7.3 before fix pack 2.
How can remote authenticated users exploit CVE-2021-38268?
Remote authenticated users with site member permissions can exploit CVE-2021-38268 by adding new forms by default.
Where can I find more information about CVE-2021-38268?
You can find more information about CVE-2021-38268 on the Liferay website and the Liferay Developer Portal.