Liferay Portal Incorrect Default Permissions Vulnerability - CVE-2021-33333
The Portal Workflow module in Liferay Portal 7.3.2 and earlier and Liferay DXP 7.0 before fix pack 93 7.1 before fix pack 19 and 7.2 before fix pack 6 does not properly check user permission which allows remote authenticated users to view and delete workflow submissions via crafted URLs.