Description
Liferay Portal and Liferay DXP allow users to upload an unlimited amount of files through the object entries attachment fields, the files are stored in the document_library allowing an attacker to cause a potential DDoS.
Severity
5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L)
Affected Version(s)
- Liferay Portal 7.4.0 through 7.4.3.132
- Liferay DXP 2025.Q1.0 through 2025.Q1.4
- Liferay DXP 2024.Q4.0 through 2024.Q4.10
- Liferay DXP 2024.Q3.1 through 2024.Q3.13
- Liferay DXP 2024.Q2.0 through 2024.Q2.13
- Liferay DXP 2024.Q1.1 through 2024.Q1.15
- Liferay DXP 7.4 GA through U92
Fixed Version(s)
- Liferay Portal fixed on master branch
- Liferay DXP 2024.Q1.16
- Liferay DXP 2025.Q1.5
- Liferay DXP 2025.Q2.0
Publication date: Mon, 14 Jul 2025 16:59:00 +0000