Description
Liferay Portal 7.2.1, 7.3.2 and possibly earlier unsupported versions includes the following libraries which have known vulnerabilities:
- Netty 4.1.42
- Dom4j 2.1.1
- Apache CXF 2.7.11
- Apache Olingo 4.4.0
- jQuery 3.4.1
- TwelveMonkeys ImageIO 3.3.2
Severity
Severity 2
Fixed Version(s)
- Liferay Portal 7.3.3
- September 2020 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page.
Acknowledgments
Some issues reported by Arun Das
Publication date: Mon, 31 Aug 2020 17:00:00 +0000