com.liferay:com.liferay.layout.page.template.service@3.0.2 vulnerabilities

  • latest version

    4.0.115

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the com.liferay:com.liferay.layout.page.template.service package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    SQL Injection

    com.liferay:com.liferay.layout.page.template.service is an enterprise information portal

    Affected versions of this package are vulnerable to SQL Injection in the Layout module, via a crafted payload injected into a page template's 'Name' field.

    How to fix SQL Injection?

    Upgrade com.liferay:com.liferay.layout.page.template.service to version 4.0.17 or higher.

    [,4.0.17)
    • L
    Regular Expression Denial of Service (ReDoS)

    com.liferay:com.liferay.layout.page.template.service is an enterprise information portal

    Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) in LayoutPageTemplateEntryUpgradeProcess, which allows remote attackers to consume excessive server resources by sending a malicious name field value for a layout prototype.

    How to fix Regular Expression Denial of Service (ReDoS)?

    Upgrade com.liferay:com.liferay.layout.page.template.service to version 4.0.21 or higher.

    [,4.0.21)