Fixed
Pinned fields
Click on the next to a field label to start pinning.
Details
Assignee
EE SupportEE SupportReporter
Enterprise Release HUEnterprise Release HUPriority
LowComponents
Details
Details
Assignee
EE Support
EE SupportReporter
Enterprise Release HU
Enterprise Release HUPriority
Components
Zendesk Support
Zendesk Support
Zendesk Support
Created October 28, 2020 at 4:38 PM
Updated August 2, 2021 at 12:10 AM
Resolved December 14, 2020 at 8:04 AM
Liferay DXP 7.2 allows access to Cross-origin resource sharing (CORS) protected resources even if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the user email address and the current CSRF token.