The best way to keep your installation of Liferay Portal secure is to always use the latest release - currently Liferay Portal 7.3 GA1. However, we’ve been hearing from you in the community that using the latest release can be challenging, especially if you need to upgrade from one major version to another. So, to make it easier to keep your Liferay Portal instance secure, the Community Security Team will periodically release source patches for the last GA release of each major version. For example, patches will be released for 7.1 GA4 and 7.0 GA7. For more information on working with patches, please see Patching Liferay Portal.
Without further ado, you can find the patches below. All vulnerabilities fixed in these patches have already been fixed in Liferay Portal 7.2 GA2. Please refer to the readme file for a list of issues addressed in each patch:
- Liferay Portal 7.1 GA4: Patch | Readme
- Liferay Portal 7.0 GA7: Patch | Readme
- Liferay Portal 6.2 GA6: Patch | Readme
Note: This release includes patches for Liferay Portal 6.2 and 7.0. However, these versions are very old and there are no plans to release additional patches for these versions. If you are running Liferay Portal 6.2 or 7.0, please consider upgrading as soon as possible.
Update:
Thanks to Arun Das, binary builds of the patch is available for Liferay Portal 6.2: Link 1 | Link 2
Disclaimer: Binary patches have not been tested by Liferay
