CST-7229 Mail server DoS via MembershipRequestService

Description

In Liferay Portal 7.0.6, 7.1.3, 7.2.0, and possibly earlier unsupported versions, the MembershipRequestService APIs can be used in a denial-of-service attack on the mail server.

Severity

Severity 2

Fixed Version(s)

Publication date: Mon, 02 Aug 2021 08:57:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.