CVE-2023-3426: Medium severity Liferay Digital Experience Platform vulnerability
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-3426?
CVE-2023-3426 is a vulnerability in Liferay Portal and Liferay DXP that allows remote authenticated users to obtain a list of all organizations without proper permission checks.
What is the severity of CVE-2023-3426?
CVE-2023-3426 has a severity value of 4.3, which is considered medium.
How does CVE-2023-3426 affect Liferay Portal and Liferay DXP?
CVE-2023-3426 affects Liferay Portal versions 7.4.3.81 through 7.4.3.85, and Liferay DXP versions 7.4 update 81 through 85.
How can remote authenticated users exploit CVE-2023-3426?
Remote authenticated users can exploit CVE-2023-3426 by accessing the organization selector and obtaining a list of all organizations.
Is there a fix for CVE-2023-3426?
Yes, upgrading to Liferay Portal version 7.4.3.86 or higher, or Liferay DXP version 7.4 update 86 or higher, will fix CVE-2023-3426.