Description
Liferay Portal 7.1.0 and earlier is vulnerable to denial-of-service (DoS) attacks via file uploads because of vulnerabilities in Apache Tika.
Severity
Severity 1
Fixed Version(s)
- Liferay Portal 7.1.1
- March 2020 source patch for Liferay Portal 7.0.6. Details for working with source patches can be found on the Patching Liferay Portal page.
- March 2020 source patch for Liferay Portal 6.2.5. Details for working with source patches can be found on the Patching Liferay Portal page.
Acknowledgments
This issue was reported by Sergio Amanzanedo
Publication date: Thu, 05 Mar 2020 07:35:00 +0000