The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-20036 | Liferay Portal and Liferay DXP does not properly check user permission |
Github GHSA |
GHSA-22wc-7wmm-v4cc | Liferay Portal and Liferay DXP does not properly check user permission |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 13 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay digital Experience Platform
|
|
| CPEs | cpe:2.3:a:liferay:dxp:7.0:fix_pack_94:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_18:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:-:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_1:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_2:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_3:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_4:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_5:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_6:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_7:*:*:*:*:*:* |
cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_93:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_94:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_18:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:-:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_2:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_3:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_4:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_5:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_6:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_7:*:*:*:*:*:* |
| Vendors & Products |
Liferay dxp
|
Liferay digital Experience Platform
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:50:41.434Z
Reserved: 2021-05-20T00:00:00
Link: CVE-2021-33327
No data.
Status : Modified
Published: 2021-08-03T19:15:08.787
Modified: 2025-05-13T18:17:51.450
Link: CVE-2021-33327
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA