GHSA-f372-9rcj-8w2c

Suggest an improvement
Source
https://github.com/advisories/GHSA-f372-9rcj-8w2c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-f372-9rcj-8w2c/GHSA-f372-9rcj-8w2c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f372-9rcj-8w2c
Aliases
Published
2025-09-23T00:32:03Z
Modified
2025-09-23T15:42:31Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Liferay Portal and DXP allows users to add a note to a different virtual instance
Details

Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote authenticated users to from one virtual instance to add a note to an order in a different virtual instance via the _com_liferay_commerce_order_web_internal_portlet_CommerceOrderPortlet_commerceOrderId parameter.

Database specific
{
    "cwe_ids":  [
        "CWE-639"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-09-23T15:10:51Z",
    "nvd_published_at":  "2025-09-22T23:15:37Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / com.liferay.commerce:com.liferay.commerce.service

Package

Name
com.liferay.commerce:com.liferay.commerce.service
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.commerce/com.liferay.commerce.service

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.0.164

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
2.*
2.0.0
2.0.1
3.*
3.0.0
4.*
4.0.0
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
5.*
5.0.0
5.0.1
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
5.4.7
5.4.8
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.5.6
5.6.0
5.7.0
5.7.1
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.8.5
5.8.6
6.*
6.0.0
6.0.1
6.1.0
7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.1.0
7.1.1
8.*
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.1.8
8.1.9
8.1.10
8.1.11
8.1.12
8.1.13
8.1.14
8.1.15
8.1.16
8.1.17
8.1.18
8.1.19
8.1.20
8.1.21
8.1.22
8.1.23
8.1.24
8.1.25
8.1.26
8.1.27
8.1.28
8.1.29
8.1.30
8.1.31
8.1.32
8.1.33
8.1.34
8.1.35
8.1.36
8.1.37
9.*
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.20
9.0.21
9.0.22
9.0.23
9.0.24
9.0.25
10.*
10.0.0
10.0.1
10.0.2
10.0.3
10.0.4
10.0.5
10.0.6
10.0.7
10.0.8
10.0.9
10.0.10
10.0.11
10.0.12
10.0.13
10.0.14
10.0.15
10.0.16
10.0.17
10.0.18
10.0.19
10.0.20
10.0.21
10.0.22
10.0.23
10.0.24
10.0.25
10.0.26
10.0.27
10.0.28
10.0.29
10.0.30
10.0.31
10.0.32
10.0.33
10.0.34
10.0.35
10.0.36
10.0.37
10.0.38
10.0.39
10.0.40
10.0.41
10.0.42
10.0.43
10.0.44
10.0.45
10.0.46
10.0.47
10.0.48
10.0.49
10.0.50
10.0.51
10.0.52
10.0.53
10.0.54
10.0.55
10.0.56
10.0.57
10.0.58
10.0.59
10.0.60
10.0.61
10.0.62
10.0.63
10.0.64
10.0.65
10.0.66
10.0.67
10.0.68
10.0.69
10.0.70
10.0.71
10.0.72
10.0.73
10.0.74
10.0.75
10.0.76
10.0.77
10.0.78
10.0.79
10.0.80
11.*
11.0.0
11.0.1
11.0.2
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7
11.0.8
11.0.9
11.0.10
11.0.11
11.0.12
11.0.13
11.0.14
11.0.15
11.0.16
11.0.17
11.0.18
11.0.19
11.0.20
11.0.21
11.0.22
11.0.23
11.0.24
11.0.25
11.0.26
11.0.27
11.0.28
11.0.29
11.0.30
11.0.31
11.0.32
11.0.33
11.0.34
11.0.35
11.0.36
11.0.37
11.0.38
11.0.39
11.0.40
11.0.41
11.0.42
11.0.43
11.0.44
11.0.45
11.0.46
11.0.47
11.0.48
11.0.49
11.0.50
11.0.51
11.0.52
11.0.53
11.0.54
11.0.55
11.0.56
11.0.57
11.0.58
11.0.59
11.0.60
11.0.61
11.0.62
11.0.63
11.0.64
11.0.65
11.0.66
11.0.67
11.0.68
11.0.69
11.0.70
11.0.71
11.0.72
11.0.73
11.0.74
11.0.75
11.0.76
11.0.77
11.0.78
11.0.79
11.0.80
11.0.81
11.0.82
11.0.83
11.0.84
11.0.85
11.0.86
11.0.87
11.0.88
11.0.89
11.0.90
11.0.91
11.0.92
11.0.93
11.0.94
11.0.95
11.0.96
11.0.97
11.0.98
11.0.99
11.0.100
11.0.101
11.0.102
11.0.103
11.0.104
11.0.105
11.0.106
11.0.107
11.0.108
11.0.109
11.0.110
11.0.111
11.0.112
11.0.113
11.0.114
11.0.115
11.0.116
11.0.117
11.0.118
11.0.119
11.0.120
11.0.121
11.0.122
11.0.123
11.0.124
11.0.125
11.0.126
11.0.127
11.0.128
11.0.129
11.0.130
11.0.131
11.0.132
11.0.133
11.0.134
11.0.135
11.0.136
11.0.137
11.0.138
11.0.139
11.0.140
11.0.141
11.0.142
11.0.143
11.0.144
11.0.145
11.0.146
11.0.147
11.0.148
11.0.149
11.0.150
11.0.151
11.0.152
11.0.153
11.0.154
11.0.155
11.0.156
11.0.157
11.0.158
11.0.159
11.0.160
11.0.161
11.0.162
11.0.163

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-f372-9rcj-8w2c/GHSA-f372-9rcj-8w2c.json"