CST-7055 Open redirect prevention circumvention

Description

In Liferay Portal 7.0 CE GA7, a flaw in the code used to prevent open redirects allows some crafted URLs to circumvent the open redirect prevention logic.

Severity

Severity 2

Fixed Version(s)

Publication date: Wed, 04 Jul 2018 08:06:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.