com.liferay:com.liferay.object.dynamic.data.mapping.form.field.type@1.0.60 vulnerabilities

  • latest version

    1.0.69

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    2 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the com.liferay:com.liferay.object.dynamic.data.mapping.form.field.type package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Files or Directories Accessible to External Parties

    Affected versions of this package are vulnerable to Files or Directories Accessible to External Parties files uploaded by object entry and stored in document_library, via URL.

    How to fix Files or Directories Accessible to External Parties?

    Upgrade com.liferay:com.liferay.object.dynamic.data.mapping.form.field.type to version 1.0.65 or higher.

    [,1.0.65)
    • M
    Allocation of Resources Without Limits or Throttling

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the attachment upload functionality. An attacker can exhaust system resources and disrupt service availability by uploading an unlimited number of files to the document_library.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade com.liferay:com.liferay.object.dynamic.data.mapping.form.field.type to version 1.0.64 or higher.

    [,1.0.64)