Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
All files within the application's WAR folder is accessible via crafted URL. Severity 1 Liferay Portal 7.0.5 Liferay Portal 7.0.5
Severity 2 Open redirect vulnerability in the Asset Publisher application allows remote attackers to redirect users to arbitrary web sites. Liferay Portal 7.0.5 Liferay Portal 7.0.5 This issue was...
Severity 1 Liferay Portal 7.0.5 Liferay Portal 7.0.5 Unauthenticated users can modify system settings to gain administration privileges.
Severity 1 In Liferay Portal 7.0.4 and earlier, when Xuggler is enabled for video conversion, a large number of temporary files may be created during video playback, which allows remote users to...
Passwords are visible to administrators in the System Settings section of the Control Panel. Severity 2 Liferay Portal 7.0.5 Liferay Portal 7.0.5
Severity 2 Multiple permission issue allows users to perform actions on resources which they are not authorized to perform. Liferay Portal 7.0.5 Liferay Portal 7.0.5
Liferay Portal 7.0.5 Some vulnerabilities reported by Marko Winkler Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML into a page....
Severity 2 In a shared environment (e.g., a computer at a library or internet cafe), a user's reminder query answer may be accessible by another user. Liferay Portal 7.0.4 Liferay Portal 7.0.4
Severity 2 User's email address, screen name or user id (depending on the authentication method) is exposed in URL. Liferay Portal 7.0.4 Liferay Portal 7.0.4
Liferay Portal 7.0.4 Liferay Portal 7.0.4 Multiple permission issue allows users to perform actions on resources which they are not authorized to perform. Severity 2
Severity 2 Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML into a page. Liferay Portal 7.0.4 Liferay Portal 7.0.4
7.0.3-ce-ga4-security-1.0 patch (source) In Liferay Portal 7.0 CE GA4, the path to all OSGi bundles is exposed via crafted URL. Severity 1
In Liferay Portal 7.0 CE GA3, Velocity and FreeMarker templates does not properly restrict the use of some variables, which allow any user with permission to create a template to insert arbitrary...
In Liferay Portal 7.0 CE GA4, multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML into a page. Severity 2 7.0.3-ce-ga4-security-1.0...
7.0.3-ce-ga4-security-1.0 patch (source) March 2020 source patch for Liferay Portal 6.2.5. Details for working with source patches can be found on the Patching Liferay Portal page. In Liferay...
In Liferay Portal 7.0 CE GA4, AggregateFilter, MinifierFilter and DynamicCSSFilter allows unauthenticated users to cause a denial of service (disk consumption) via crafted URL. Severity 1...
Liferay Portal 7.0.0 Liferay Portal 7.0.0 This issue was reported by Marko Winkler Severity 2 Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web...
User credentials may appear in the logs if the user authenticates using basic authentication. Severity 2 Liferay Portal 7.0.0 Liferay Portal 7.0.0
Severity 2 Insufficient permission checking in Message Board and Comments allows unauthorized users to edit and/or delete other user's messages or comments. Liferay Portal 7.0.0 Liferay Portal...
Severity 2 Liferay Portal 7.0.0 Liferay Portal 7.0.0 This issue was reported by Spyridon Chatzimichail Users without the necessary permssion can view page configuration information the via crafted...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy