109.0.0
8 years ago
20 days ago
Known vulnerabilities in the com.liferay.portal:com.liferay.portal.impl package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | [,7.8.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) due to insufficient protection on the terms of use page. An attacker can trick a user into accepting the site's terms of use by convincing them to visit a malicious page. How to fix Cross-site Request Forgery (CSRF)? Upgrade | [,5.25.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Observable Discrepancy due to the handling of different responses based on site existence or user permissions. An attacker can discover the existence of sites by enumerating URLs. Note: This is only exploitable if How to fix Observable Discrepancy? Upgrade | [,7.8.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Insecure Default Initialization of Resource such that the default configuration does not require users to verify their email addresses, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property How to fix Insecure Default Initialization of Resource? Upgrade | [,5.5.4) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) in How to fix Arbitrary File Write via Archive Extraction (Zip Slip)? Upgrade | [,47.1.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Open Redirect via the How to fix Open Redirect? Upgrade | [,7.9.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Access Restriction Bypass by not properly checking user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI. How to fix Access Restriction Bypass? Upgrade | [,6.05) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Information Exposure. User's passwords are stored in the database if workflow is enabled for new users. This allows attackers with access to the database to obtain the user's unencrypted password. How to fix Information Exposure? Upgrade | [,5.11.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Improper Validation. Password reset tokens are still valid after a user changes their password, which allows remote attackers to change the user’s password via the old password reset token. How to fix Improper Validation? Upgrade | [,5.7.3) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Information Exposure. It allows remote attackers to enumerate user email addresses via the forgot password functionality. The How to fix Information Exposure? Upgrade | [,5.11.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Improper Authorization. It does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration. How to fix Improper Authorization? Upgrade | [,5.9.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Privilege Escalation. It allows remote authenticated users with permission to update or edit users to take over a company administrator user account by editing the company administrator user. How to fix Privilege Escalation? Upgrade | [,5.16.4) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Arbitrary File Access. The property How to fix Arbitrary File Access? Upgrade | [7.2.0,7.4.0)[0,7.1.3) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Deserialization of Untrusted Data. Deserialization of Untrusted Data in Liferay Portal allows remote attackers to execute arbitrary code via JSON web services (JSONWS). How to fix Deserialization of Untrusted Data? Upgrade | [4.0.0,4.7.0)[3.0.0,3.49.0)[,2.65.3) |