Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Cross-site scripting (XSS) vulnerability in the journal module in Liferay Portal 7.3.0 through 7.3.3 allows remote attackers to inject arbitrary web script or HTML via the...
Severity 2 The Portal Workflow module in Liferay Portal 7.3.2 and earlier, does not properly check user permission, which allows remote authenticated users to view and delete workflow submissions...
Liferay Portal 7.3.3 This issue was reported by Prajwal Khante Liferay Portal 7.2.0 through 7.3.2 allows access to Cross-origin resource sharing (CORS) protected resources if the user is only...
Severity 2 Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1 allows remote attackers to redirect users to arbitrary external URLs via the 'redirect'...
Severity 2 The Flags module in Liferay Portal 7.3.1 and earlier does not limit the rate at which content can be flagged as inappropriate, which allows remote authenticated users to spam the site...
Liferay Portal 7.3.3 May 2021 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. There is no fix available for Liferay...
Severity 2 The Layout module in Liferay Portal 7.1.0 through 7.3.1 does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the...
Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4 and 7.3.5 allow remote attackers to inject arbitrary web script or HTML via the...
Liferay Portal 7.3.6 Liferay Portal 7.3.6 May 2021 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. Severity 2...
Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5 allows remote attackers to inject arbitrary web script or...
Severity 2 The Portal Store module in Liferay Portal 7.0.0 through 7.3.5 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle...
Severity 2 Liferay Portal 7.3.6 Liferay Portal 7.3.6 Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 allows remote attackers to...
Severity 2 Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5 allows remote attackers to inject arbitrary web...
Severity 2 The SimpleCaptcha implementation in Liferay Portal 7.3.4 and 7.3.5 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions...
The JSON web services in Liferay Portal 7.3.4 and earlier, the JSON web service may contain overly verbose error messages, which allows remote attackers to use the contents of error messages to...
Liferay Portal 7.3.6 Liferay Portal 7.3.6 Severity 2 The Data Engine module in Liferay Portal 7.3.0 through 7.3.5 does not check permissions in DataDefinitionResourceImpl....
May 2021 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. In Liferay Portal 7.2.0 and 7.2.1, a reflected cross-site...
The redirect module in Liferay Portal 7.3.2 does not limit the number of URLs that result in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by...
Severity 1 Liferay Portal before 7.3.3 does not restrict the size of ‘multipart/form-data’ encoded form post, which allows remote authenticated users to conduct denial-of-service attacks by...
Liferay Portal 7.3.3 September 2020 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. Liferay Portal 7.3.3 Cross-site...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy