GHSA-5gh9-g62h-f35m

Suggest an improvement
Source
https://github.com/advisories/GHSA-5gh9-g62h-f35m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5gh9-g62h-f35m/GHSA-5gh9-g62h-f35m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5gh9-g62h-f35m
Aliases
Published
2022-05-24T19:10:03Z
Modified
2025-05-28T20:57:12Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers
Details

Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user.

Database specific
{
    "cwe_ids":  [
        "CWE-269",
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-05-28T20:14:34Z",
    "nvd_published_at":  "2021-08-03T22:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven
com.liferay.portal:release.portal.bom

Package

Name
com.liferay.portal:release.portal.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.portal.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.3
Fixed
7.3.5

Affected versions

7.*
7.0.6
7.0.6-1
7.0.6-2
7.1.0
7.1.1
7.1.2
7.1.3
7.1.3-1
7.2.0
7.2.1
7.2.1-1
7.3.0
7.3.0-1
7.3.1
7.3.1-1
7.3.2
7.3.2-1
7.3.3
7.3.3-1
7.3.4

Database specific

last_known_affected_version_range
"<= 7.3.4"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5gh9-g62h-f35m/GHSA-5gh9-g62h-f35m.json"
com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.1.10.fp20

Affected versions

7.*
7.1.10
7.1.10.fp1
7.1.10.fp2
7.1.10.fp3
7.1.10.fp4
7.1.10.fp5
7.1.10.fp6
7.1.10.fp7
7.1.10.fp8
7.1.10.fp9
7.1.10.fp10
7.1.10.fp11
7.1.10.fp12
7.1.10.fp13
7.1.10.fp14
7.1.10.fp15
7.1.10.fp16
7.1.10.fp17
7.1.10.fp18
7.1.10.fp19

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5gh9-g62h-f35m/GHSA-5gh9-g62h-f35m.json"
com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.2.0
Fixed
7.2.10.fp9

Affected versions

7.*
7.2.1
7.2.10
7.2.10.fp1
7.2.10.fp1-1
7.2.10.fp2
7.2.10.fp3
7.2.10.fp4
7.2.10.fp5
7.2.10.fp6
7.2.10.fp7
7.2.10.fp8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5gh9-g62h-f35m/GHSA-5gh9-g62h-f35m.json"