CVE-2021-29040 Overly verbose JSON web services errors

Description

The JSON web services in Liferay Portal 7.3.4 and earlier, the JSON web service may contain overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused attacks.

Severity

Severity 2

Fixed Version(s)

There is no fix available for Liferay Portal 7.0 and 7.1. Please upgrade to Liferay Portal 7.3.

Publication date: Mon, 10 May 2021 16:00:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.