Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Severity 2 Multiple permission issue exists in Liferay Portal 7.1 CE GA1 which allows users to perform actions on resources which they are not authorized to perform. Liferay Portal 7.1.1 Liferay...
Severity 2 In Liferay Portal 7.1 CE GA1, multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML into a page. Liferay Portal 7.1.1 Liferay...
An open redirect vulnerability exits with Blogs RSS and tunnel-web in Liferay Portal 7.1 CE GA1. Severity 2 Liferay Portal 7.1.1 Liferay Portal 7.1.1 This issue was reported by Tiago Sintra
Liferay Portal 7.1.1 Liferay Portal 7.1.1 This issue was reported by Osama Mahmood Severity 2 In Liferay Portal 7.1 CE GA1, other sessions are not terminated when a user changes their password.
In LIferay Portal 7.0 CE GA7, a theoretical OS command injection vulnerability exists in SendmailHook. Severity 2 Liferay Portal 7.1.0 7.0.6-ce-ga7-security-1.0 patch (source) By default, the...
Severity 2 The CSV files that are exported by Liferay Portal 7.0 CE GA7 (user export, DDL export and Form export) is susceptible to CSV injection if the CSV file is opened by some spreadsheet...
Liferay Portal 7.1.0 7.0.6-ce-ga7-security-1.0 patch (source) Liferay Portal 7.1.0 In Liferay Portal 7.0 CE GA7, A cross-site request forgery (CSRF) vulnerability exist with comments. An attacker...
Severity 2 In Liferay Portal 7.0 CE GA7, the password for a Form's REST data provider does not obfuscate the password leading to password disclosure. Liferay Portal 7.1.0 Liferay Portal 7.1.0...
In Liferay Portal 7.0 CE GA7, a flaw in the code used to prevent open redirects allows some crafted URLs to circumvent the open redirect prevention logic. Severity 2 Liferay Portal 7.1.0...
Liferay Portal 7.1.0 Liferay Portal 7.1.0 7.0.6-ce-ga7-security-1.0 patch (source) Severity 2 In Liferay Portal 7.0 CE GA7, blogs titles are visible to users without the appropriate view...
Some vulnerabilities reported by Gergő Czuczor Severity 2 In Liferay Portal 7.0 CE GA7, multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or...
Multiple cross-site request forgery (CSRF) vulnerabilities allow remote attackers to execute unwanted actions in the portal. Workaround: Remove the following lines from the...
Severity 1 In Liferay Portal 7.0.5 and earlier, the Web Proxy portlet/application allows remote attackers to execute arbitrary code via supplied stylesheet. Patched versions of the portal will...
Liferay Portal 7.0.6 The portal may be vulnerable to BREACH attacks if the portal is using HTTPS and compression (GZip) is enabled. Workaround: Disable compression by setting...
Severity 2 The "doAsUserId" parameter used by Administrators for impersonating another user can be leaked to third party sites. Liferay Portal 7.0.6 Liferay Portal 7.0.6
The asset tag API leaks information about the user who created the asset tag. Severity 2 Liferay Portal 7.0.6 Liferay Portal 7.0.6
Liferay Portal 7.0.6 Liferay Portal 7.0.6 Severity 2 Multiple permission issue allows users to perform actions on resources which they are not authorized to perform.
A reflected cross-site scripting (XSS) vulnerability exist on the JSONWS API page. An attacker can potentially exploit this security vulnerability to insert malicious JavaScript into a page....
Severity 2 Apache Commons Email is vulnerable to SMTP header injection (CVE-2017-9801). Liferay Portal is not vulnerable, however, custom modules/apps using the Commons Email JAR bundled with the...
Liferay Portal 7.0.5 Liferay Portal 7.0.5 Severity 2 Content spoofing is possible via URL manipulation in applications that suppor tags. An attacker can potentially exploit this security...
All files within the application's WAR folder is accessible via crafted URL. Severity 1 Liferay Portal 7.0.5 Liferay Portal 7.0.5
Severity 2 Open redirect vulnerability in the Asset Publisher application allows remote attackers to redirect users to arbitrary web sites. Liferay Portal 7.0.5 Liferay Portal 7.0.5 This issue was...
Severity 1 Liferay Portal 7.0.5 Liferay Portal 7.0.5 Unauthenticated users can modify system settings to gain administration privileges.
Severity 1 In Liferay Portal 7.0.4 and earlier, when Xuggler is enabled for video conversion, a large number of temporary files may be created during video playback, which allows remote users to...
Passwords are visible to administrators in the System Settings section of the Control Panel. Severity 2 Liferay Portal 7.0.5 Liferay Portal 7.0.5
Severity 2 Multiple permission issue allows users to perform actions on resources which they are not authorized to perform. Liferay Portal 7.0.5 Liferay Portal 7.0.5
Liferay Portal 7.0.5 Some vulnerabilities reported by Marko Winkler Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML into a page....
Severity 2 In a shared environment (e.g., a computer at a library or internet cafe), a user's reminder query answer may be accessible by another user. Liferay Portal 7.0.4 Liferay Portal 7.0.4
Severity 2 User's email address, screen name or user id (depending on the authentication method) is exposed in URL. Liferay Portal 7.0.4 Liferay Portal 7.0.4
Liferay Portal 7.0.4 Liferay Portal 7.0.4 Multiple permission issue allows users to perform actions on resources which they are not authorized to perform. Severity 2
Severity 2 Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML into a page. Liferay Portal 7.0.4 Liferay Portal 7.0.4
7.0.3-ce-ga4-security-1.0 patch (source) In Liferay Portal 7.0 CE GA4, the path to all OSGi bundles is exposed via crafted URL. Severity 1
In Liferay Portal 7.0 CE GA3, Velocity and FreeMarker templates does not properly restrict the use of some variables, which allow any user with permission to create a template to insert arbitrary...
In Liferay Portal 7.0 CE GA4, multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML into a page. Severity 2 7.0.3-ce-ga4-security-1.0...
7.0.3-ce-ga4-security-1.0 patch (source) March 2020 source patch for Liferay Portal 6.2.5. Details for working with source patches can be found on the Patching Liferay Portal page. In Liferay...
In Liferay Portal 7.0 CE GA4, AggregateFilter, MinifierFilter and DynamicCSSFilter allows unauthenticated users to cause a denial of service (disk consumption) via crafted URL. Severity 1...
Liferay Portal 7.0.0 Liferay Portal 7.0.0 This issue was reported by Marko Winkler Severity 2 Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web...
User credentials may appear in the logs if the user authenticates using basic authentication. Severity 2 Liferay Portal 7.0.0 Liferay Portal 7.0.0
Severity 2 Insufficient permission checking in Message Board and Comments allows unauthorized users to edit and/or delete other user's messages or comments. Liferay Portal 7.0.0 Liferay Portal...
Severity 2 Liferay Portal 7.0.0 Liferay Portal 7.0.0 This issue was reported by Spyridon Chatzimichail Users without the necessary permssion can view page configuration information the via crafted...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy