CST-7220 Directory traversal with Page Fragment exports

Description

In Liferay Portal 7.1.3, 7.2.1 and possibly earlier unsupported versions, exporting Page Fragments and Page Fragment Collections can overwrite files in the filesystem with the following filenames: collection.json, fragment.json, index.css, index.html, index.js and index.json.

Severity

Severity 2

Fixed Version(s)

Publication date: Tue, 09 Jun 2020 02:00:00 +0000