4.3
CVE-2021-33330
- EPSS 0.21%
- Published 03.08.2021 19:15:08
- Last modified 13.05.2025 18:17:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the targeted user’s email address and current CSRF token.
Data is provided by the National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version7.2 Update-
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_1
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_2
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_3
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_4
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_5
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_6
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_7
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_8
Liferay ≫ Liferay Portal Version >= 7.2.0 < 7.3.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.21% | 0.401 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|