com.liferay.portal:com.liferay.portal.impl
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.liferay.portal:com.liferay.portal.implpage 1 of 1
- CVE-2020-15840MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.1.32020-09-24
vulnerable: 1.0.0 ... 7.1.2 (1300 versions)
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
- CVE-2021-29050HIGHCVSS 8.8EG 8.8✓ Fixed in 5.25.02024-02-20
vulnerable: 1.0.0 ... 5.9.0 (1140 versions)
Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7.2 before fix pack 11 allows remote attackers to accept the site's terms of use via social…
- CVE-2021-33321HIGHCVSS 7.5EG 7.5✓ Fixed in 5.11.02021-08-03
vulnerable: 1.0.0 ... 5.9.0 (1051 versions)
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.passwo…
- CVE-2021-33322HIGHCVSS 7.5EG 7.5✓ Fixed in 5.7.32021-08-03
vulnerable: 1.0.0 ... 5.7.2 (1036 versions)
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens are not invalidated after a user changes their password, which allows remote attackers to…
- CVE-2022-26595MEDIUMCVSS 4.3EG 4.3✓ Fixed in 7.7.92022-04-19
vulnerable: 1.0.0 ... 7.7.8 (1319 versions)
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the…
- CVE-2022-41414MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.0.02022-10-07
vulnerable: 1.0.0 ... 7.8.8 (1328 versions)
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
Check whether com.liferay.portal:com.liferay.portal.impl is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.liferay.portal:com.liferay.portal.impl CVEs against the assets you own.
Start Free Scan →