Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hm7-r8f3-423h

Опубликовано: 30 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet

Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to access arbitrary CSS and JSS files and load the files multiple times via the query string in a URL.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

>= 7.4.0-ga1, <= 7.4.3.107-ga107

7.4.3.108-ga108

Наименование

com.liferay.portal:com.liferay.portal.impl

maven
Затронутые версииВерсия исправления

< 96.0.0

96.0.0

EPSS

Процентиль: 46%
0.00235
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.2
nvd
4 месяца назад

Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to access arbitrary CSS and JSS files and load the files multiple times via the query string in a URL.

EPSS

Процентиль: 46%
0.00235
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-22