Uploaded image for project: 'PUBLIC - Liferay Portal Enterprise Edition'
  1. PUBLIC - Liferay Portal Enterprise Edition
  2. LPE-2148

Some JSONService allows unauthenticated access

Details

    Description

      Some JSONService allows unauthenticated access to the service. Specifically, CounterServiceUtil, DLServiceUtil, and MailServiceUtil is vulnerable.

      Attachments

        Issue Links

          Activity

            People

              oscar.gao Oscar Gao (Inactive)
              brian.chan Brian Chan
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Packages

                  Version Package
                  5.1 EE SP5 (5.1.8)
                  5.2 EE SP4 (5.2.8)