Description
The RSS portlet and FuseMail integration in Liferay Portal 7.0.2 and earlier uses a version of Apache Commons HttpClient which allows man-in-the-middle attackers to intercept and modify communication with the portal.
Severity
Severity 1
Fixed Version(s)
- Liferay Portal 7.0.3
- March 2020 source patch for Liferay Portal 6.2.5. Details for working with source patches can be found on the Patching Liferay Portal page.
Publication date: Mon, 02 Mar 2020 07:21:00 +0000