[MAVEN:GHSA-W275-M8CR-HF2V] Liferay Portal denial-of-service vulnerability

Severity Moderate
Affected Packages 4
Fixed Packages 4
CVEs 1

The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.

ID
MAVEN:GHSA-W275-M8CR-HF2V
Severity
moderate
URL
https://github.com/advisories/GHSA-w275-m8cr-hf2v
Published
2024-02-08T06:30:23
(7 months ago)
Modified
2024-02-20T15:59:05
(7 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.liferay.portal/release.portal.bom com.liferay.portal release.portal.bom >= 7.2.0 < 7.4.3.27
Fixed pkg:maven/com.liferay.portal/release.portal.bom com.liferay.portal release.portal.bom = 7.4.3.27
Affected pkg:maven/com.liferay.portal/release.dxp.bom com.liferay.portal release.dxp.bom >= 7.4.0 < 7.4.13.u27
Fixed pkg:maven/com.liferay.portal/release.dxp.bom com.liferay.portal release.dxp.bom = 7.4.13.u27
Affected pkg:maven/com.liferay.portal/release.dxp.bom com.liferay.portal release.dxp.bom >= 7.3.0 < 7.3.10.u6
Fixed pkg:maven/com.liferay.portal/release.dxp.bom com.liferay.portal release.dxp.bom = 7.3.10.u6
Affected pkg:maven/com.liferay.portal/release.dxp.bom com.liferay.portal release.dxp.bom >= 7.2.0 < 7.2.10.fp19
Fixed pkg:maven/com.liferay.portal/release.dxp.bom com.liferay.portal release.dxp.bom = 7.2.10.fp19
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...