CVE-2021-33333

The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pack 6, does not properly check user permission, which allows remote authenticated users to view and delete workflow submissions via crafted URLs.
Configurations

Configuration 1

cpe:2.3:a:liferay:dxp:7.0:fix_pack_81:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_13:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_14:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_24:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_25:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_26:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_27:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_28:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_3+:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_30:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_33:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_35:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_36:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_39:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_40:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_41:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_42:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_43:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_44:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_45:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_46:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_47:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_48:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_49:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_50:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_51:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_52:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_53:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_54:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_56:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_57:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_58:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_59:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_60:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_61:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_64:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_65:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_66:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_67:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_68:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_69:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_70:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_71:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_72:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_73:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_75:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_76:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_78:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_79:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_80:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_2:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_3:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_4:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_5:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:fix_pack_1:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_6:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_7:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_8:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_9:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_10:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_11:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_12:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_13:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_14:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_15:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_16:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_1:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_2:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_3:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_4:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_5:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:-:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:-:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.2:-:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_17:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.1:fix_pack_18:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_82:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_83:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_84:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_85:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_86:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_87:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_88:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_89:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_90:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_91:*:*:*:*:*:*
cpe:2.3:a:liferay:dxp:7.0:fix_pack_92:*:*:*:*:*:*

Information

Published : 2021-08-03 09:15

Updated : 2021-08-11 05:01


NVD link : CVE-2021-33333

Mitre link : CVE-2021-33333

Products Affected
No products.
CWE
CWE-276

Incorrect Default Permissions