// For flags

CVE-2021-33327

 

Severity Score

4.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.

El módulo Portlet Configuration de Liferay Portal versiones 7.2.0 hasta 7.3.3, y Liferay DXP versiones 7.0 fix pack 93 y 94, versiones 7.1 fix pack 18, y versiones 7.2 anteriores a fix pack 8, no comprueba apropiadamente los permisos de usuarios, que permite a usuarios autenticado remoto visualizar el rol de invitado y de usuario incluso si la "Role Visibility" está habilitada

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-05-20 CVE Reserved
  • 2021-08-03 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-276: Incorrect Default Permissions
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.0
Search vendor "Liferay" for product "Dxp" and version "7.0"
fix_pack_93
Affected
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.0
Search vendor "Liferay" for product "Dxp" and version "7.0"
fix_pack_94
Affected
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.1
Search vendor "Liferay" for product "Dxp" and version "7.1"
fix_pack_18
Affected
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.2
Search vendor "Liferay" for product "Dxp" and version "7.2"
-
Affected
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.2
Search vendor "Liferay" for product "Dxp" and version "7.2"
fix_pack_1
Affected
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.2
Search vendor "Liferay" for product "Dxp" and version "7.2"
fix_pack_2
Affected
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.2
Search vendor "Liferay" for product "Dxp" and version "7.2"
fix_pack_3
Affected
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.2
Search vendor "Liferay" for product "Dxp" and version "7.2"
fix_pack_4
Affected
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.2
Search vendor "Liferay" for product "Dxp" and version "7.2"
fix_pack_5
Affected
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.2
Search vendor "Liferay" for product "Dxp" and version "7.2"
fix_pack_6
Affected
Liferay
Search vendor "Liferay"
Dxp
Search vendor "Liferay" for product "Dxp"
7.2
Search vendor "Liferay" for product "Dxp" and version "7.2"
fix_pack_7
Affected
Liferay
Search vendor "Liferay"
Liferay Portal
Search vendor "Liferay" for product "Liferay Portal"
>= 7.2.0 < 7.3.4
Search vendor "Liferay" for product "Liferay Portal" and version " >= 7.2.0 < 7.3.4"
-
Affected