Description
Liferay Portal 7.x before 7.3.2, does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
Severity
Severity 1
Fixed Version(s)
- Liferay Portal 7.3.2
- June 2020 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page.
- June 2020 source patch for Liferay Portal 7.1.3. Details for working with source patches can be found on the Patching Liferay Portal page.
Notes
CVE-2020-13444 has been assigned to this vulnerability.
Publication date: Tue, 09 Jun 2020 02:00:00 +0000