CVE-2023-3426: Liferay Portal and Liferay DXP Organization Selector Does Not Check User Permissions
(updated )
The organization selector before 4.0.14 from Liferay Portal (7.4.3.81 through 7.4.3.85), and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
References
Code Behaviors & Features
Detect and mitigate CVE-2023-3426 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →