com.liferay.portal:com.liferay.portal.kernel@19.0.1 vulnerabilities

  • latest version

    156.0.0

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    6 days ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the com.liferay.portal:com.liferay.portal.kernel package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Access Control Bypass

    Affected versions of this package are vulnerable to Access Control Bypass due to unauthorized access to object definition via search. The Object module does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object definition.

    How to fix Access Control Bypass?

    Upgrade com.liferay.portal:com.liferay.portal.kernel to version 94.0.0 or higher.

    [,94.0.0)