CST-6240 User with impersonate permission can elevate privileges to portal administrator

Description

Liferay Portal 6.2.5 and earlier does not properly check permissions, which allows remote authenticated users to impersonate, edit, or delete administrators.

Workaround: Remove the User.DELETE, User.IMPERSONATE, User.PERMISSIONS and User.UPDATE permissions from and role or user.

Severity

Severity 1

Fixed Version(s)

Publication date: Mon, 02 Mar 2020 07:21:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.