CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 2.7. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
CVE
CVE-2023-33946
Severity
LOW
CVSS
2.7
EPSS
0.61%
Original NVD Description
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page.
Related CVEs
Other vulnerabilities affecting the same vendor(s)