CST-7054 Blog titles leaked to users without view permission

Description

In Liferay Portal 7.0 CE GA7, blogs titles are visible to users without the appropriate view permission. Only the title is leaked and the user cannot view the content of the blog entry.

Severity

Severity 2

Fixed Version(s)

Publication date: Wed, 04 Jul 2018 08:06:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.