<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Getting Redirected to Login portlet when accessing /image</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=120583608" />
  <subtitle>Getting Redirected to Login portlet when accessing /image</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=120583608</id>
  <updated>2026-04-03T23:22:59Z</updated>
  <dc:date>2026-04-03T23:22:59Z</dc:date>
  <entry>
    <title>RE: Getting Redirected to Login portlet when accessing /image</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=120683756" />
    <author>
      <name>Vilmos Papp</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=120683756</id>
    <updated>2021-03-12T11:12:01Z</updated>
    <published>2021-03-12T11:12:01Z</published>
    <summary type="html">&lt;p&gt;If it's an EE version, you can open a support ticket ask whether a
  security fix is avaliable for your problem.&lt;/p&gt;</summary>
    <dc:creator>Vilmos Papp</dc:creator>
    <dc:date>2021-03-12T11:12:01Z</dc:date>
  </entry>
  <entry>
    <title>RE: RE: Getting Redirected to Login portlet when accessing /image</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=120681643" />
    <author>
      <name>Gaurav Pandey</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=120681643</id>
    <updated>2021-03-12T18:07:26Z</updated>
    <published>2021-03-12T07:14:21Z</published>
    <summary type="html">&lt;p&gt;Thanks Manish, this is what we did to get the work done.&lt;/p&gt;</summary>
    <dc:creator>Gaurav Pandey</dc:creator>
    <dc:date>2021-03-12T07:14:21Z</dc:date>
  </entry>
  <entry>
    <title>RE: Getting Redirected to Login portlet when accessing /image</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=120681638" />
    <author>
      <name>Gaurav Pandey</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=120681638</id>
    <updated>2021-03-12T18:07:26Z</updated>
    <published>2021-03-12T07:13:37Z</published>
    <summary type="html">&lt;p&gt;Thanks for the help, this is what we did and got it blocked from web server.&lt;/p&gt;</summary>
    <dc:creator>Gaurav Pandey</dc:creator>
    <dc:date>2021-03-12T07:13:37Z</dc:date>
  </entry>
  <entry>
    <title>RE: Getting Redirected to Login portlet when accessing /image</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=120582660" />
    <author>
      <name>Manish Yadav</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=120582660</id>
    <updated>2021-03-12T07:12:41Z</updated>
    <published>2021-02-03T02:00:14Z</published>
    <summary type="html">&lt;p&gt;You may restrict url at web server level. (httpd.conf ) &lt;/p&gt;</summary>
    <dc:creator>Manish Yadav</dc:creator>
    <dc:date>2021-02-03T02:00:14Z</dc:date>
  </entry>
  <entry>
    <title>Getting Redirected to Login portlet when accessing /image</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=120583607" />
    <author>
      <name>Gaurav Pandey</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=120583607</id>
    <updated>2021-02-01T10:57:54Z</updated>
    <published>2021-02-01T09:25:45Z</published>
    <summary type="html">&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;We recently received a Vulnerability that is as below (Liferay 6.2 EE)&lt;/p&gt;
&lt;p&gt;When we manupulate custom login portlet URL.
  https://www.mycustomlogin/login to https://www.mycustomlogin/image I
  get redirected to the Liferay Login portlet which exposes the full URL (https://www.mycustomlogin/inicio?p_p_state=maximized&amp;amp;p_p_mode=view&amp;amp;saveLastPath=false&amp;amp;_58_struts_action=%2Flogin%2Flogin&amp;amp;&lt;strong&gt;p_p_id=58&lt;/strong&gt;&amp;amp;p_p_lifecycle=0&amp;amp;_58_redirect=%2Fimage)&lt;/p&gt;
&lt;p&gt;and after this URL can be modified to get access to search
  portlet(p_p_id=3). can you help us with the way to change this
  behavious as we do not want to expose our control panel login and
  search portlet.&lt;/p&gt;
&lt;p&gt;I am new to liferay but i tried introducing a custom filter but it
  looks request is getting intercepted before request is received by my filter.&lt;/p&gt;
&lt;p&gt;Thanks in Advance.&lt;/p&gt;</summary>
    <dc:creator>Gaurav Pandey</dc:creator>
    <dc:date>2021-02-01T09:25:45Z</dc:date>
  </entry>
</feed>
