CVE-2023-33948: High severity liferay liferay portal vulnerability
The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.68
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33948?
The severity of CVE-2023-33948 is high.
What is the description of CVE-2023-33948?
CVE-2023-33948 allows remote attackers to download any file from Document and Media via a crafted URL.
Which software versions are affected by CVE-2023-33948?
Liferay Portal 7.4.3.67 and Liferay DXP 7.4 update 67 are affected by CVE-2023-33948.
How can I mitigate the vulnerability in CVE-2023-33948?
Update Liferay Portal to version 7.4.3.68 or later.
Where can I find more information about CVE-2023-33948?
You can find more information about CVE-2023-33948 at the following references: [Link 1](https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33948), [Link 2](https://nvd.nist.gov/vuln/detail/CVE-2023-33948), [Link 3](https://github.com/advisories/GHSA-w6f8-mxf5-4vf8).