Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
June 2020 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. June 2020 source patch for Liferay Portal 7.1.3. Details...
Liferay Portal 7.1.3 and 7.2.1 includes the following libraries which have known vulnerabilities: Apache Commons Compress 1.18 Bouncy Castle Provider 1.45 c3p0 0.9.5.3 Jackson Databind 2.9.9.3...
Severity 2 Liferay Portal 7.2.1 June 2020 source patch for Liferay Portal 7.1.3. Details for working with source patches can be found on the Patching Liferay Portal page. Liferay Portal 7.2.1 In...
Some vulnerabilities reported by Casey Erdmann, Giuseppino Cadeddu and Simone Cinti Severity 2 Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.1.3, 7.2.1 and possibly...
Liferay Portal 7.x before 7.2.1, is vulnerable to Server-Side Request Forgery (SSRF) via DDM REST Data Provider which allows an attacker access to sensitive information. This issue exists because...
In Liferay Portal 7.1.3 and possibly earlier unsupported versions, the JAX-RS API does not check for a CSRF token, which allows remote attackers to perform Cross-site request forgery (CSRF)...
Severity 1 In Liferay Portal 7.2.1 and earlier, the 'Test LDAP Connection' feature can be exploited to obtain the LDAP password. Liferay Portal 7.2.1 Liferay Portal 7.2.1 June 2020 source patch for...
Liferay Portal 7.2.1 In Liferay Portal 7.2.1 and earlier, a Java deserialization vulnerability exists when the portal is clustered. Communication between the nodes can be intercepted and modified....
Severity 1 In Liferay Portal before 7.3.2, the template API does not restrict user access to to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted...
Severity 1 Liferay Portal 7.x before 7.3.2, does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data...
Liferay Portal 7.1.3 and possibly earlier unsupported versions is bundled with with Apache Tika 1.20 which contains known vulnerabilities. Severity 2 March 2020 source patch for Liferay Portal...
March 2020 source patch for Liferay Portal 7.1.3. Details for working with source patches can be found on the Patching Liferay Portal page. Liferay Portal 7.1.3 and possibly earlier unsupported...
Liferay Portal 7.1.3 and possibly earlier unsupported versions, is bundled with withJasig CAS Client 3.1.12 which contains known vulnerabilities. Severity 2 March 2020 source patch for Liferay...
Liferay Portal 7.1.3 and possibly earlier unsupported versions, is bundled with with Jackson Databind 2.9.8 which contains known vulnerabilities. Severity 2 March 2020 source patch for Liferay...
March 2020 source patch for Liferay Portal 7.1.3. Details for working with source patches can be found on the Patching Liferay Portal page. In Liferay Portal 7.1.3 and possibly earlier unsupported...
Liferay Portal 7.2.1 March 2020 source patch for Liferay Portal 7.1.3. Details for working with source patches can be found on the Patching Liferay Portal page. Liferay Portal 7.2.1 This issue was...
In Liferay Portal 7.1.3 and possibly earlier unsupported versions, the 'com.liferay.frontend.js.lodash.web' bundle includes Lodash 4.17.4 which has known vulnerabilities. Severity 2 March 2020...
Liferay Portal 7.0.0 through 7.0.6 does not properly verify permission when creating pages which may lead to attackers changing portal settings and gaining access to sensitive information. Severity...
Severity 1 Liferay Portal 7.1.0 and earlier is vulnerable to denial-of-service (DoS) attacks via file uploads because of vulnerabilities in Apache Tika. Liferay Portal 7.1.1 Liferay Portal 7.1.1...
In Liferay Portal 7.2.0 and earlier, users can update their password via JSONWS without supplying their current password. An attacker can exploit this to modify a user password by leveraging XSS,...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy