Liferay Portal and Liferay DXP fails to check permissions to view sites/groups
Moderate severity
GitHub Reviewed
Published
Apr 20, 2022
to the GitHub Advisory Database
•
Updated Jul 14, 2025
Package
Affected versions
< 7.7.9
Patched versions
7.7.9
>= 7.2.0, < 7.2.10.fp13
>= 7.3.0, < 7.3.10.fp2
7.2.10.fp13
7.3.10.fp2
Description
Published by the National Vulnerability Database
Apr 19, 2022
Published to the GitHub Advisory Database
Apr 20, 2022
Last updated
Jul 14, 2025
Reviewed
Jul 14, 2025
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.
References