Liferay Portal Incorrect Default Permissions Vulnerability - CVE-2021-33324
The Layout module in Liferay Portal 7.1.0 through 7.3.1 and Liferay DXP 7.1 before fix pack 20 and 7.2 before fix pack 5 does not properly check permission of pages which allows remote authenticated users without view permission of a page to view the page via a site39s page administration.