VYPR

Bitnami package

liferay

pkg:bitnami/liferay

Vulnerabilities (44)

  • CVE-2021-38265Mar 2, 2022
    affected < 7.3.0fixed 7.3.0

    Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web script or HTML when creating a collection page via the _com_liferay_asset_list_web_portlet_AssetListPortlet_title parameter.

  • CVE-2021-38266Mar 2, 2022
    affected >= 7.0.0, <= 7.0.0

    The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by at

  • CVE-2021-38268Mar 2, 2022
    affected < 7.2.1fixed 7.2.1

    The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users

  • CVE-2020-15839Sep 22, 2020
    affected >= 7.1.0, <= 7.1.0

    Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.

Page 3 of 3