The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update_1"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_2"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_3"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_4"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_5"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_6"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_7"
},
{
"introduced": "0"
},
{
"last_affected": "7.4-update_1"
},
{
"introduced": "0"
},
{
"last_affected": "7.4-update_2"
},
{
"introduced": "7.3.3"
},
{
"fixed": "7.4.3.35"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39975.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update_8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update_9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_18"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_19"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_20"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_21"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_24"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_26"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_27"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_28"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_30"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_31"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_34"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_9"
}
]
}
]