VYPR
Medium severity6.5NVD Advisory· Published Jun 10, 2020· Updated Jun 17, 2026

CVE-2020-13444

CVE-2020-13444

Description

Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.liferay.portal:release.portal.bomMaven
>= 7.0.0, < 7.3.27.3.2
com.liferay.portal:release.dxp.bomMaven
>= 7.0.0, < 7.0.10.fp927.0.10.fp92
com.liferay.portal:release.dxp.bomMaven
>= 7.1.0, < 7.1.10.fp197.1.10.fp19
com.liferay.portal:release.dxp.bomMaven
>= 7.2.0, < 7.2.10.fp77.2.10.fp7

Affected products

10
  • Liferay/Portal7 versions
    cpe:2.3:a:liferay:liferay_portal:7.1.1:ga2:*:*:community:*:*:*+ 6 more
    • cpe:2.3:a:liferay:liferay_portal:7.1.1:ga2:*:*:community:*:*:*
    • cpe:2.3:a:liferay:liferay_portal:7.1:ga1:*:*:community:*:*:*
    • cpe:2.3:a:liferay:liferay_portal:7.1:ga2:*:*:community:*:*:*
    • cpe:2.3:a:liferay:liferay_portal:7.1:ga3:*:*:community:*:*:*
    • cpe:2.3:a:liferay:liferay_portal:7.2:ga1:*:*:community:*:*:*
    • cpe:2.3:a:liferay:liferay_portal:7.3:ga1:*:*:community:*:*:*
    • cpe:2.3:a:liferay:liferay_portal:7.3:ga2:*:*:community:*:*:*
  • Liferay/Portaldescription
  • ghsa-coords2 versions
    >= 7.0.0, < 7.0.10.fp92+ 1 more
    • (no CPE)range: >= 7.0.0, < 7.0.10.fp92
    • (no CPE)range: >= 7.0.0, < 7.3.2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.