CVE-2021-33327 Unauthorized users can view the Guest and User roles

Description

The portlet configuration module in Liferay Portal 7.2.0 through 7.3.3 does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.

Severity

Severity 2

Fixed Version(s)

Publication date: Mon, 10 May 2021 16:00:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.