114.1.0
9 years ago
2 months ago
Known vulnerabilities in the com.liferay.portal:com.liferay.portal.impl package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via insecure domain validation on How to fix Server-side Request Forgery (SSRF)? Upgrade | [,113.1.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data via the How to fix Insertion of Sensitive Information Into Sent Data? Upgrade | [,108.1.1) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | [,110.0.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Timing Attack via the password encryptor during the login process. An attacker can determine the existence of user accounts by analyzing differences in server response times to crafted authentication requests. How to fix Timing Attack? Upgrade | [,110.0.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Information Exposure via the How to fix Information Exposure? Upgrade | [,111.0.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | [,109.1.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Open Redirect via the Note: This vulnerability is bypass for CVE-2022-28977 How to fix Open Redirect? Upgrade | [,25.0.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Observable Discrepancy via the authentication process. An attacker can obtain information about the existence of user accounts by analyzing differences in response times. How to fix Observable Discrepancy? Upgrade | [,40.0.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Insecure Default Initialization of Resource via the How to fix Insecure Default Initialization of Resource? Upgrade | [,37.0.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Open Redirect via the How to fix Open Redirect? Upgrade | [,31.0.2) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Incorrect Authorization in the process that manages site membership restrictions when the "Limit membership to members of the parent site" option is enabled. An attacker can gain unauthorized access to a child site and perform actions without proper authorization by adding users who are not members of the parent site. How to fix Incorrect Authorization? Upgrade | [,7.8.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Incorrect Authorization in the User and Organizations section of the Control Panel. An attacker can gain unauthorized ability to modify their own permissions by leveraging only the VIEW user permission. How to fix Incorrect Authorization? Upgrade | [,8.2.1) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data via the Control Panel. An attacker can obtain sensitive user information by enumerating user screen names and accessing the page's title. How to fix Insertion of Sensitive Information Into Sent Data? Upgrade | [,8.0.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | [,7.8.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) due to insufficient protection on the terms of use page. An attacker can trick a user into accepting the site's terms of use by convincing them to visit a malicious page. How to fix Cross-site Request Forgery (CSRF)? Upgrade | [,5.25.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Observable Discrepancy due to the handling of different responses based on site existence or user permissions. An attacker can discover the existence of sites by enumerating URLs. Note: This is only exploitable if How to fix Observable Discrepancy? Upgrade | [,7.8.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Insecure Default Initialization of Resource such that the default configuration does not require users to verify their email addresses, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property How to fix Insecure Default Initialization of Resource? Upgrade | [,5.5.4) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) in How to fix Arbitrary File Write via Archive Extraction (Zip Slip)? Upgrade | [,47.1.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Open Redirect via the How to fix Open Redirect? Upgrade | [,7.9.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Access Restriction Bypass by not properly checking user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI. How to fix Access Restriction Bypass? Upgrade | [,6.05) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Information Exposure. User's passwords are stored in the database if workflow is enabled for new users. This allows attackers with access to the database to obtain the user's unencrypted password. How to fix Information Exposure? Upgrade | [,5.11.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Improper Validation. Password reset tokens are still valid after a user changes their password, which allows remote attackers to change the user’s password via the old password reset token. How to fix Improper Validation? Upgrade | [,5.7.3) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Information Exposure. It allows remote attackers to enumerate user email addresses via the forgot password functionality. The How to fix Information Exposure? Upgrade | [,5.11.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Improper Authorization. It does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration. How to fix Improper Authorization? Upgrade | [,5.9.0) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Privilege Escalation. It allows remote authenticated users with permission to update or edit users to take over a company administrator user account by editing the company administrator user. How to fix Privilege Escalation? Upgrade | [,5.16.4) |
com.liferay.portal:com.liferay.portal.impl is a package part of Liferay. Affected versions of this package are vulnerable to Arbitrary File Access. The property How to fix Arbitrary File Access? Upgrade | [7.2.0,7.4.0)[0,7.1.3) |