Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6pgj-w687-9c8c

Опубликовано: 21 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Liferay Portal fails to verify messages from the cluster network is trusted

Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to send malicious data to the Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions that will treat it as trusted data via unauthenticated cluster messages.

Пакеты

Наименование

com.liferay:com.liferay.portal.cluster.multiple

maven
Затронутые версииВерсия исправления

< 5.0.35

5.0.35

EPSS

Процентиль: 5%
0.00021
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to send malicious data to the Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions that will treat it as trusted data via unauthenticated cluster messages.

EPSS

Процентиль: 5%
0.00021
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-346