MEDIUM
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with the forms "Access in Site Administration" permission to view all forms and form entries in a site via the forms section in site administration
Published Aug 3, 2021
4.3
MEDIUMCVSS 3.1
EPSS 0.86%
Description
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with the forms "Access in Site Administration" permission to view all forms and form entries in a site via the forms section in site administration.
Affected products
No data.
OR
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- ≥ 7.0.0 · < 7.3.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-20042 Advisory
- https://github.com/advisories/GHSA-g37f-j8hh-736f Advisory
- https://issues.liferay.com/browse/LPE-17039 x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-33334
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120748332 x_refsource_CONFIRMRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-20042 | Advisory | |
| https://github.com/advisories/GHSA-g37f-j8hh-736f | Advisory | |
| https://issues.liferay.com/browse/LPE-17039 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-33334 | ||
| https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120748332 | x_refsource_CONFIRMRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 3, 2021
Updated Aug 3, 2024
Reserved May 20, 2021
Link CVE-2021-33334
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-20042 GHSA-G37F-J8HH-736F Assigner mitre
Published Aug 3, 2021
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2021-20042