CVE-2023-33941: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.53 - Upgrade
Upgrade
Liferay Portalto a version that resolves this vulnerability.Fixed in 7.4.3.41 through 7.4.3.52 - Upgrade
Upgrade
Liferay DXPto a version that resolves this vulnerability.Fixed in 7.4 update 41 through 52
Event History
Frequently Asked Questions
What is CVE-2023-33941?
CVE-2023-33941 is a vulnerability related to multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52.
How severe is CVE-2023-33941?
CVE-2023-33941 has a severity rating of 6.1, making it a medium-level vulnerability.
Which software versions are affected by CVE-2023-33941?
CVE-2023-33941 affects Liferay Portal 7.4.3.41 through 7.4.3.52 and Liferay DXP 7.4 update 41 through 52.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-33941?
CVE-2023-33941 is classified under CWE-79, which is the code injection vulnerability category.
Where can I find more information about CVE-2023-33941?
More information about CVE-2023-33941 can be found at the following reference link: [CVE-2023-33941](https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33941)