Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
The default GenericPortlet implementation is vulnerable to denial-of-service (DoS) attacks and information leak (CVE-2015-1926). As a part of this fix, the JSR 286 Specification JAR (portlet.jar)...
This ticket covers various cross-site scripting (XSS) issues in Liferay Portal 6.2 CE GA3 that are addressed by the CST patch. LPS-55962 Incorrect escaping in liferay-ui:app-view-search-entry...
Due to a requirement in Section 4.2.5 of the JSR 329 Specification, CVE-2015-5176 exists in the Liferay Faces Bridge API dependency. For more information about patch availability, see the blog...
LPS-44182 Reflected XSS in edit layout LPS-44196 Stored XSS in Asset Publisher and WCM Display portlets via OpenOffice conversion file extensions LPS-44197 Reflected XSS in *Directory portlets...
This issue was reported by Tomas Polesovsky A zero-day security vulnerability in the ActionForms object in Struts 1.x allows remote attackers to manipulate the class loader. In some environments,...
6.2.1-ce-ga2-security-2.0 patch (source) A zero-day security vulnerability in the ActionForms object in Struts 1.x allows remote attackers to manipulate the class loader. In some environments, this...
LPS-43278 XSS in Message Boards LPS-43476 Stored XSS in Shopping portlet LPS-43653 Various XSS in Layouts admin portlet LPS-43660 Stored XSS in QuickNote LPS-42795 XSS issue in shopping portlet ...
A security vulnerability in the Apache Commons FileUpload before 1.3.1 allows remote attackers to cause a denial of service by manipulating the request header. In addition to patching Liferay...
This issue was reported by Christian Schneider The portal is vulnerable to XML external entity (XXE) processing in 6.2.2. This can lead to disclosure of confidential data or a denial-of-service...
Note that there are two binary patches which fix both LPS-51061 (this report) and LPS-51094, as well as all previous CST fixes for this release. You only need to apply one of these, not both....
The forgot password feature in the Sign In portlet allows e-mail address in the portal to be enumerated. Workaround: Disable forgot password emails Severity 3 Note that there are two binary patches...
This ticket covers various permission checking issues in Liferay Portal 6.2 CE GA3 that are addressed by the CST patch, including: Permissions are not correctly checked when creating folders in...
This fix covers various XSS issues uncovered in Liferay applications shipped with Liferay Portal CE 6.2 GA2 (6.2.1). This issue also resolves CERT VU#100972 Severity 2 6.2.1-ce-ga2-security-3.0...
This issue fixes several XSS issues in 6.2.2: User profile, Message Boards, portlet.vm, and control panel. Severity 2 Note that there are two binary patches which fix both LPS-51061 (this report)...
This fix addresses two vulnerabilities which allow a guest user to obtain a list of the sites and workflow definition in the portal by manipulating the URL. The user can only view the name of the...
This issue was discovered and reported by Bob Brinks This ticket resolves two unvalidated redirects, one related to the Document and Media portlet one related to CAS, that may be used in a phishing...
The portal is vulnerable to HTTP host header attacks. This vulnerability can be used for web cache poisoning or for password reset poisoning. Severity 1 Note that there are two binary patches which...
Severity 2 This fix groups several minor XSS issues discovered in Liferay Portal 6.2.0 in to a single CST patch. The following fixes are included: LPS-43095 - XSS issue in DDL - ability to inject...
Note that there are two binary patches which fix both LPS-51094 (this report) and LPS-51061 (as well as all previous CST fixes). You only need to apply one of these, not both. Binary Patch 1: The...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy