Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
March 2020 source patch for Liferay Portal 7.1.3. Details for working with source patches can be found on the Patching Liferay Portal page. In Liferay 7.1.0 through 7.1.3, unauthorized users can...
Severity 2 In Liferay Portal 7.1.3, 7.2.0 and possibly earlier unsupported versions, the Sign In widget may expose the user's email address and/or password in the page's HTML source. This may allow...
Severity 2 In Liferay Portal 7.1.3, 7.2.0 and possibly earlier unsupported versions, the search results from the Search Bar widget uses links that redirect users to HTTP instead of HTTPS. Liferay...
In Liferay Portal 7.1.3, 7.2.0 and possibly earlier unsupported versions, the 'com.liferay.map.openstreetmap' bundle loads the npm package, leaflet, using HTTP instead of HTTPS. Severity 2 Liferay...
Liferay Portal 7.2.1 Liferay Portal 7.2.1 Severity 2 In Liferay Portal 7.2 CE GA1 and possibly earlier unsupported versions, an open redirect vulnerability exists in Account Settings.
In Liferay Portal 7.1 CE GA4, 7.2 CE GA1 and possibly earlier unsupported versions, the Hello World widget reveals the DXP version information. The verbosity of the version information can now be...
Severity 1 In Liferay Portal 7.2.0 and earlier contains a remote code execution (RCE) vulnerability via JSON web services (JSONWS). Workaround: Disable JSONWS by setting the portal.property...
Liferay Portal 7.2.1 March 2020 source patch for Liferay Portal 7.1.3. Details for working with source patches can be found on the Patching Liferay Portal page. Liferay Portal 7.2.1 In Liferay...
Severity 2 Liferay Portal 7.2 CE GA1 includes the following libraries which have known vulnerabilities: Apache Commons BeanUtils 1.9.2 Apache Tika 1.20 Jackson Databind 2.9.9 Jasig CAS Client...
Multiple permission issue exists in Liferay Portal 7.2 CE GA1 which allows users to perform actions on resources which they are not authorized to perform. Severity 2 Liferay Portal 7.2.1 Liferay...
Liferay Portal 7.2.1 Liferay Portal 7.2.1 Severity 2 In Liferay Portal 7.2 CE GA1, multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML...
Liferay Faces Alloy 2.0.2 (source) Liferay Faces Alloy 2.0.2 (source) Liferay Faces Alloy 3.0.2 (source) To install, remove any old versions of Liferay Faces Alloy and place the fixed version of...
To install, remove any old versions of Liferay Faces Alloy from your WAR and place the new version of Liferay Faces Alloy in each of your Liferay Faces WARs in the WEB-INF/lib directory. Make sure...
Binary patch (source) To install, place patch in each of your Liferay Faces WARs in the WEB-INF/lib directory. The dependency can be included via Maven, Gradle, or Ivy. In a Maven project pom.xml...
Severity 1 Liferay Portal 7.1.0 and earlier is vulnerable to remote code execution using Web Content/DDM templates. Workaround: Review permissions and do not grant untrusted users permissions to...
When defining permissions for a role in Liferay Portal 7.1 CE GA3 and older unsupported versions, some permissions may be selected by default. This may unintentionally lead to some users receiving...
Severity 2 In Liferay Portal 7.1 CE GA3 and older unsupported versions, an open redirect vulnerability exist in the Language Selector widget. Liferay Portal 7.1.3 Liferay Portal 7.1.3
Liferay Portal 7.1.3 In Liferay Portal 7.1 CE GA3 and older unsupported versions, a path traversal vulnerability exists in poller. Severity 2 Liferay Portal 7.1.3
Severity 2 Liferay Portal 7.1 CE GA3 includes the following libraries which have known vulnerabilities: Apache Batik 1.7 Apache HttpClient 4.1 Apache PDFBox 2.0.9 Apache Tika 1.18 c3p0 0.9.5.2...
In Liferay Portal 7.1 CE GA3, multiple cross-site scripting (XSS) vulnerabilities exists which allow remote attackers to inject arbitrary web script or HTML into a page. Severity 2 Liferay Portal...
Liferay Portal 7.1.3 Liferay Portal 7.1.3 Severity 1 Liferay Portal 7.1 CE GA3 and older unsupported versions and older unsupported versions is vulnerable to Server-Side Request Forgery (SSRF) via...
In Liferay Portal 7.1 CE GA3 and older unsupported versions, Message Boards post that are marked as "Anonymous" can be associated with the user who posted it. This issue exists because of an...
Severity 2 In Liferay Portal 7.1 CE GA3 and older unsupported versions, a company's secret key is accessible via templates. Liferay Portal 7.1.3 Liferay Portal 7.1.3
Liferay Portal 7.1.3 Liferay Portal 7.1.3 Severity 2 In Liferay Portal 7.1 CE GA3 and older unsupported versions, user password hashes and password reminder answers may be appear in the logs if a...
Multiple permission issue exists in Liferay Portal 7.1 CE GA3 which allows users to perform actions on resources which they are not authorized to perform. Severity 2 Liferay Portal 7.1.3 Liferay...
Severity 2 Message boards post that are marked as "Anonymous" can be associated with the user who posted it. Liferay Portal 7.1.2 Liferay Portal 7.1.2
Severity 2 Liferay Portal 7.1.2 Liferay Portal 7.1.2 An open redirect vulnerability exist in Liferay Portal 7.1 CE with the <liferay-ui:header> tag.
Severity 2 In Liferay Portal 7.1 CE, an unexpected error may produce an overly verbose error message that is visible to end users. Liferay Portal 7.1.2 Liferay Portal 7.1.2
User login in Liferay Portal 7.1 CE is vulnerable to Cross-Site Request Forgery (CSRF) attacks. Severity 2 Liferay Portal 7.1.2 Liferay Portal 7.1.2
Severity 1 A bug in Liferay Portal CE 7.1 CE allows any authenticated user to change the password of another user, including an administrator. Once a user has access to an administrator account, a...
Liferay Portal 7.1.2 Multiple permission issue exists in Liferay Portal 7.1 CE GA2 which allows users to perform actions on resources which they are not authorized to perform. Severity 2 Liferay...
Severity 2 A stored cross-site scripting (XSS) vulnerability exits with the image resolution information in Adaptive Media in Liferay CE 7.1 GA2. Liferay Portal 7.1.2 Liferay Portal 7.1.2
Severity 1 Liferay Portal 7.1.0 and earlier is vulnerable to remote code execution (RCE) via deserialization of JSON data. Liferay Portal 7.1.1 Liferay Portal 7.1.1 March 2020 source patch for...
Liferay Portal 7.1.1 March 2020 source patch for Liferay Portal 7.0.6. Details for working with source patches can be found on the Patching Liferay Portal page. March 2020 source patch for Liferay...
Severity 2 The password reset token may be leaked to 3rd party website in Liferay Portal 7.1 CE. Out of the box, the password reset token is not leaked to any 3rd party website. However, if the...
The default configuration for Liferay Portal 7.0.0 through 7.1.0 allow attackers to conduct XML External Entity (XXE) attacks via XSL templates in XSL Content and Web Content. Workaround: 1....
Liferay Portal 7.1.1 Liferay Portal 7.1.1 Severity 2 In Liferay Portal 7.1 CE GA1, users are normally required to enter their current password if they want to change their password. However, the...
Notification emails sent to users in Liferay Portal 7.1 CE GA1 is vulnerable to HTML injection. An attacker can exploit this vulnerability for phishing attacks. Severity 2 Liferay Portal 7.1.1...
Severity 2 Liferay Portal 7.1.0 and earlier is vulnerable to a Server-Side Request Forgery (SSRF) via Web Content templates and Application Display Templates (ADT) which may allow an attacker...
Severity 2 Liferay Portal 7.1.1 Liferay Portal 7.1.1 An LDAP injection vulnerability exits in Liferay 7.1 CE GA1 with user group names.
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy