GHSA-769c-p92r-xgxj
GitHub Security Advisory
Liferay portal has unauthorized access to object definition via search
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object definition.
Affected Packages
Maven
com.liferay.portal:release.portal.bom
Affected versions:
7.4.3.4
(fixed in 7.4.3.61)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 15, 2025 6:32 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.