CVE-2023-33946: Medium severity liferay digital experience platform vulnerability
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33946?
The severity of CVE-2023-33946 is medium.
Which versions of Liferay Portal are affected by CVE-2023-33946?
Liferay Portal versions 7.4.3.4 through 7.4.3.48 are affected by CVE-2023-33946.
How does CVE-2023-33946 impact Liferay Portal?
CVE-2023-33946 allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration.
How can I fix CVE-2023-33946?
To fix CVE-2023-33946, update to Liferay Portal version 7.4.3.49 or later.
Where can I find more information about CVE-2023-33946?
You can find more information about CVE-2023-33946 [here](https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33946).