January 2022 : Security patch for Liferay Portal 7.3

Downloads:

All vulnerabilities fixed in these patches have already been fixed in Liferay Portal 7.4 GA5. Please refer to the readme file for a list of issues addressed in each patch. For more information on working with patches, please see Patching Liferay Portal .

Thanks to Arun Das and Dominik Marks, binary builds of the patches are available:

Disclaimer: Binary patches have not been tested by Liferay.

Blogs

Thanks for creating this patch! I discovered a bug: after the portal-impl.jar is overwritten, the redirect to the login doesn't work anymore. When I try to access a page without guest privileges (without login), I get the error that the page does not exist. Actually I should be redirected to the login portlet in that case.