GHSA-h9ww-wjg4-jvvg

Suggest an improvement
Source
https://github.com/advisories/GHSA-h9ww-wjg4-jvvg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-h9ww-wjg4-jvvg/GHSA-h9ww-wjg4-jvvg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h9ww-wjg4-jvvg
Aliases
Published
2022-09-23T00:00:46Z
Modified
2025-07-16T15:42:16.943438Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module
Details

The Translation module before v2.0.58 from Liferay Portal (v7.4.3.12 through v7.4.3.36), and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2025-07-16T15:23:43Z",
    "nvd_published_at": "2022-09-22T01:15:00Z",
    "cwe_ids": [
        "CWE-269",
        "CWE-862"
    ],
    "severity": "MODERATE"
}
References

Affected packages

Maven / com.liferay:com.liferay.translation.web

Package

Name
com.liferay:com.liferay.translation.web
View open source insights on deps.dev
Purl
pkg:maven/com.liferay/com.liferay.translation.web

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.58

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.20
1.0.21
1.0.22
1.0.23
1.0.24
1.0.25
1.0.26
1.0.27
1.0.28
1.0.29
1.0.30
1.0.31
1.0.32

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57

Maven / com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.4.13.u8
Fixed
7.4.13.u37

Affected versions

7.*

7.4.13.u8
7.4.13.u9
7.4.13.u10
7.4.13.u15
7.4.13.u16
7.4.13.u17
7.4.13.u18
7.4.13.u19
7.4.13.u20
7.4.13.u21
7.4.13.u22
7.4.13.u23
7.4.13.u24
7.4.13.u25
7.4.13.u26
7.4.13.u27
7.4.13.u28
7.4.13.u29
7.4.13.u30
7.4.13.u31
7.4.13.u32
7.4.13.u33
7.4.13.u34
7.4.13.u35
7.4.13.u36

Database specific

{
    "last_known_affected_version_range": "<= 7.4.13.u36"
}