Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Severity 2 When JAAS is enabled, ThreadLocal may leak variables to other processes. Liferay Portal 7.0.3 Liferay Portal 7.0.3
Severity 2 Passwords are visible to administrators in the Server Administration section of the Control Panel. Liferay Portal 7.0.3 Liferay Portal 7.0.3
System settings (including credentials/passwords) may be exposed when performing a data migration. The information exposure is limited to the administrator user who executed the data migration....
Liferay Portal 7.0.3 Liferay Portal 7.0.3 Some vulnerabilities reported by Spyridon Chatzimichail Severity 2 Multiple permission issue allows users to perform actions on resources which they are...
The password history checking functionality in a password policy can be circumvented via forget password. Severity 2 Liferay Portal 7.0.3 Liferay Portal 7.0.3
Severity 2 Open redirect vulnerability in Search application allows remote attackers to redirect users to arbitrary web sites. Liferay Portal 7.0.3 Liferay Portal 7.0.3
Liferay Portal 7.0.3 March 2020 source patch for Liferay Portal 6.2.5. Details for working with source patches can be found on the Patching Liferay Portal page. Liferay Portal 7.0.3 Apache Commons...
Severity 1 Apache Tika is vulnerable to XML External Entity (XXE) processing attacks. This vulnerability can allow an attacker to access files on the file system and/or take down the portal (denial...
Unsanitized data in SessionClicks allows an attacker to cause a denial-of-service (DoS) via crafted URLs. The denial-of-service is limited to users who have clicked on the crafted URL and may...
Liferay Portal 7.0.3 Liferay Portal 7.0.3 Some vulnerabilities reported by Craig Young and Juho Nurminen Severity 2 Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to...
This issue was reported by Jacob Baines Severity 1 TunnelServlet allows remote code execution by unauthenticated users. Liferay Portal 7.0.3 Liferay Portal 7.0.3
If the log level is set to DEBUG, LDAP credentials are exposed in the logs. Severity 2 Liferay Portal 7.0.2 Liferay Portal 7.0.2
Severity 1 In Liferay Portal 7.0.1 and earlier, PDFBox does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a...
Severity 2 Liferay Portal 7.0.2 Liferay Portal 7.0.2 Editing a blog entry may reset the blog entry's permission to the default permission. This may allow a user without the necessary permission to...
Liferay Portal 7.0.2 The search result in the Search portlet may include search results which a user does not have permission to view. Severity 2 Liferay Portal 7.0.2
This issue was reported by Galina Kovbasenko Severity 2 The portal is vulnerable to open redirects for certain types of URLs. An attacker can potentially exploit this security vulnerability to...
Severity 2 This ticket covers various inline JavaScript related cross-site scripting (XSS) vulnerability. An attacker can potentially exploit this security vulnerability to insert malicious...
A reflected cross-site scripting (XSS) vulnerability exist in the <aui:form> tag. An attacker can potentially exploit this security vulnerability to insert malicious JavaScript into a page....
Severity 2 A reflected cross-site scripting (XSS) vulnerability exist in the <aui:form> tag. An attacker can potentially exploit this security vulnerability to insert malicious JavaScript into a...
Severity 2 A stored cross-site scripting (XSS) vulnerability exist in Monitoring. An attacker can potentially exploit this security vulnerability to insert malicious JavaScript into a page. Liferay...
By default, Liferay Portal gives every registered user the Power User role. When a signed in user has the Power User role, the user will have their own site and permissions to manage the site...
Liferay Portal 7.0.1 Liferay Portal 7.0.1 Severity 2 Cross-Site Request Forgery (CSRF) tokens are persisted in the database and may make it easier for an attacker to launch a CSRF attack.
An open redirect vulnerability exists with Facebook authentication. An attacker can potentially exploit this security vulnerability to redirect users to a different site. Severity 2 Liferay Portal...
Severity 2 By constructing the correct URL, some restricted Web Application Bundle (WAB) resources may be accessible. Liferay Portal 7.0.1 Liferay Portal 7.0.1
Liferay Portal 7.0.1 Liferay Portal 7.0.1 Severity 1 This ticket covers various permission issues in Liferay Portal 7.0 CE GA1 that may result in a user having permission the user should not have.
This ticket covers various cross-site scripting (XSS) issues in Liferay Portal 7.0 CE GA1 Severity 2 Liferay Portal 7.0.1 Liferay Portal 7.0.1
Velocity and FreeMarker templates are vulnerable to remote code execution (RCE) and privilege escalation. Severity 1 Note that there are two binary patches which fix this issue, as well as all...
Password policies can be configured to lock out a user after a specified number of failed login attempts. However, if a user is using digest authentication, this lock out can be circumvented....
Note that there are two binary patches which fix this issue, as well as all previous CST fixes for this release. You only need to apply one of these, not both. Binary Patch 1: The "complete" patch...
An open redirect vulnerability exists may be possible with some specially constructed domain names. An attacker can potentially exploit this security vulnerability to redirect users to a different...
A vulnerability known as "Java Deserialization Vulnerability" was discovered and Liferay Portal is potential vulnerable in the following locations: TunnelServlet: Spring-Remoting services By...
Note that there are two binary patches which fix this issue, as well as all previous CST fixes for this release. You only need to apply one of these, not both. Binary Patch 1: The "complete" patch...
This ticket covers various permission issues in Liferay Portal 6.2 CE GA6 that may result in a user having permission the user should not have. Severity 2 Note that there are two binary patches...
XSL Content portlet can be configured with any XML/XSL. The XSL Content portlet allows anyone who has permission to configure the portlet to specify any XML/XSL file. By creating the appropriate...
Flash does not strictly honor the same-origin policy. As a result, if an attacker is able to upload a malicious flash file to portal, the flash file can be used to circumvent the portal's CSRF...
The version of openid4java.jar that is currently used by the portal vulnerable to XXE attack. Severity 2 Note that there are two binary patches which fix this issue, as well as all previous CST...
Note that there are two binary patches which fix this issue, as well as all previous CST fixes for this release. You only need to apply one of these, not both. Binary Patch 1: The "complete" patch...
The MailEngine API is vulnerable to email header injection. This issue only affects users who are calling the MailEngine directly. Severity 3 Note that there are two binary patches which fix this...
This ticket covers various permission issues in Liferay Portal 6.2 CE GA3 that may result in a user having permission the user should not have. Severity 2 Note that there are two binary patches...
Note that there are two binary patches which fix this issue, as well as all previous CST fixes for this release. You only need to apply one of these, not both. Binary Patch 1: The "complete" patch...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy