CVE-2021-33331 Open redirect vulnerability in notifications

Description

Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1 allows remote attackers to redirect users to arbitrary external URLs via the 'redirect' parameter.

Severity

Severity 2

Fixed Version(s)

There is no fix available for Liferay Portal 7.0 and 7.1. Please upgrade to Liferay Portal 7.3.

Publication date: Mon, 10 May 2021 16:00:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.