Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Liferay Portal 7.0.3 Liferay Portal 7.0.3 March 2020 source patch for Liferay Portal 6.2.5. Details for working with source patches can be found on the Patching Liferay Portal page. Severity 1 The...
Liferay Portal 6.2.5 and earlier does not properly check permissions, which allows remote authenticated users to impersonate, edit, or delete administrators. Workaround: Remove the User.DELETE,...
Remote code execution vulnerability in DDM template in Liferay Portal 7.0.0 and earlier allows remote authenticated users with permission to create/edit templates to create templates that can run...
Denial-of-service (DoS) vulnerability in document library in Liferay Portal 6.2.5 and earlier allows remote attackers to cause an OutOfMemoryError by uploading a crafted PDF file. Workaround: Use...
Remote file disclosure vulnerability in DDM templates in Liferay Portal 6.2.5 and earlier allows remote authenticated users with permission create/edit templates to view any files that are readable...
March 2020 source patch for Liferay Portal 6.2.5. Details for working with source patches can be found on the Patching Liferay Portal page. The IFrame portlet in Liferay Portal 6.2.5 and earlier...
Server side request forgery (SSRF) vulnerability in pingback functionality of blogs in Liferay Portal before 7.1.0 allows remote attackers to send HTTP requests to intranet servers and conduct...
Severity 1 Denial-of-service vulnerability in DDM templates in Liferay Portal before 7.0.1 allows attackers to create templates with an infinite loop via embedded portlets. Liferay Portal 7.0.1...
The BaseBSFPortlet class contains a path traversal vulnerability via URL manipulation. Liferay Portal 7.0 CE does not use the BaseBSFPortlet class out of the box. However, developers extending...
In Liferay Portal 7.1 CE GA4 and possibly earlier unsupported versions, the LDAP credentials are transmitted in plain text. Severity 2 March 2020 source patch for Liferay Portal 7.1.3. Details for...
Liferay Portal 7.1 CE GA4 and possibly earlier unsupported versions, the 'X-Forwarded-Host' HTTP header can be used to bypass the whitelisted hosts provided in the portal property...
Liferay Portal 7.1.3 and earlier is vulnerable to remote code execution via deserialization of JSON data. Severity 1 March 2020 source patch for Liferay Portal 7.1.3. Details for working with...
March 2020 source patch for Liferay Portal 7.1.3. Details for working with source patches can be found on the Patching Liferay Portal page. The open redirect protection component in Liferay Portal...
In Liferay Portal 7.1 CE GA4 and possibly earlier unsupported versions, the user's password is visible on the screen immediately after the account creation process. Severity 2 March 2020 source...
In Liferay Portal 7.1 CE GA4 and earlier, a potential SQL injection vulnerability exist in the asset framework. Severity 1 March 2020 source patch for Liferay Portal 7.1.3. Details for working with...
March 2020 source patch for Liferay Portal 7.1.3. Details for working with source patches can be found on the Patching Liferay Portal page. Liferay Portal 7.1 CE GA4 and possibly earlier...
In Liferay Portal 7.1 CE GA4 and possibly earlier unsupported versions, users may be tricked into creating an account with an OpenID provider. If the OpenID provider is not trustworthy, an attacker...
In Liferay Portal 7.1 CE GA4, multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML into a page. Severity 2 March 2020 source patch for...
Severity 2 Liferay Portal 7.1.1 Liferay Portal 7.1.1 Liferay Portal 7.1 GA1 and possibly earlier unsupported versions truncates the regular expression field in a password policy. This may result in...
Multiple permission issue exists in Liferay Portal 7.1 CE GA4 which allows users to perform actions on resources which they are not authorized to perform. Severity 2 March 2020 source patch for...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy