The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page.
History

Tue, 22 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published: 2023-05-24T15:28:28.713Z

Updated: 2024-10-22T15:51:52.390Z

Reserved: 2023-05-24T02:36:00.165Z

Link: CVE-2023-33946

cve-icon Vulnrichment

Updated: 2024-08-02T15:54:13.397Z

cve-icon NVD

Status : Modified

Published: 2023-05-24T16:15:09.837

Modified: 2024-11-21T08:06:15.993

Link: CVE-2023-33946

cve-icon Redhat

No data.