Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Severity 2 Liferay Portal before 7.3.3 does not properly restrict access to the sitemap.xml of staged public pages, which allows remote attackers to access sitemap.xml and learn of the existence...
The Calendar widget records views by unauthenticated users in Liferay Portal 7.2.0 through 7.3.0, which allows remote attackers who view a Calendar widget to prevent changes to Instance Settings...
Liferay Portal 7.3.1 Liferay Portal 7.3.1 September 2020 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. Severity 2...
Some issues reported by Arun Das Severity 2 Liferay Portal 7.2.1, 7.3.2 and possibly earlier unsupported versions includes the following libraries which have known vulnerabilities: Netty 4.1.42...
In Liferay Portal 7.1.0 through 7.2.1, an open redirect vulnerability exist with the 'redirect' parameter in System Settings' search. Severity 2 September 2020 source patch for Liferay Portal...
The OAuth module in Liferay Portal 7.1.0 through 7.2.1 contains an authentication flaw which allows an attacker with a valid OAuth2 token to access the REST application APIs in a different Portal...
Stored cross-site scripting (XSS) vulnerability in the Document Library module in Liferay Portal 7.1.0 through 7.2.1 allows remote attackers to inject arbitrary web script or HTML via the user's...
In Liferay Portal before 7.3.3, an administrator can limit the type of images that can be used as a blog cover image. However, this protection can be circumvented via HTTP manipulation to upload...
Severity 2 Multiple cross-site scripting (XSS) vulnerabilities in the fragment module in Liferay Portal 7.1.0 through 7.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1)...
Liferay Portal 7.3.3 The login module in Liferay Portal before 7.3.3 will indicate whether an email address or screen name is in the system or not, which allows remote attackers to enumerate users...
Severity 1 Liferay Portal before 7.3.1 does not decode a URL before determining if the resource should be served, which allows remote attackers to access restricted portlet resources (e.g., files...
The staging module in Liferay Portal before 7.3.2 does not properly check user permission, which allows remote authenticated users to delete a publishing process via the staging menu. Severity 2...
Liferay Portal 7.3.1 Liferay Portal 7.3.1 Severity 2 Liferay Portal 7.3.0 does not properly check user permissions, which allows remote authenticated users to view user groups that are members of a...
Liferay Portal 7.3.0 and 7.3.1 includes the following libraries which have known vulnerabilities: Apache POI 4.1.0 Severity 2 Liferay Portal 7.3.2 Liferay Portal 7.3.2
Severity 2 Cross-site scripting (XSS) vulnerability in the portal workflow module in Liferay Portal 7.3.0 allows remote attackers to inject arbitrary web script or HTML via the user name parameter....
Liferay Portal 7.3.1 Liferay Portal 7.3.1 June 2020 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. June 2020 source...
Liferay Portal 7.1.3, 7.2.0 and possibly earlier unsupported versions, the existence of a private site and the site name is disclosed in the Blogs widget's RSS feed. Severity 2 Liferay Portal 7.2.1...
Severity 2 Liferay Portal 7.1.3, 7.2.0 and possibly earlier unsupported versions, any user can display a unconfigured instance of an instantiable widget. Liferay Portal 7.2.1 Liferay Portal 7.2.1...
June 2020 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. June 2020 source patch for Liferay Portal 7.1.3. Details...
In Liferay Portal 7.1.3, 7.2.1 and possibly earlier unsupported versions, exporting Page Fragments and Page Fragment Collections can overwrite files in the filesystem with the following filenames:...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy