CST-6240 User with impersonate permission can elevate privileges to portal administrator

Description

Liferay Portal 6.2.5 and earlier does not properly check permissions, which allows remote authenticated users to impersonate, edit, or delete administrators.

Workaround: Remove the User.DELETE, User.IMPERSONATE, User.PERMISSIONS and User.UPDATE permissions from and role or user.

Severity

Severity 1

Fixed Version(s)

Publication date: Mon, 02 Mar 2020 07:21:00 +0000