Описание
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
An SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, and 7.4 GA through update 92 allows template editors to bypass access validations via crafted URLs.
Пакеты
com.liferay.portal:release.portal.bom
>= 7.4.0, <= 7.4.3.132
Отсутствует
com.liferay.portal:release.dxp.bom
>= 2025.Q1.0, <= 2025.Q1.5
2025.Q1.6
com.liferay.portal:release.dxp.bom
>= 2024.Q4.0, <= 2024.Q4.7
Отсутствует
com.liferay.portal:release.dxp.bom
>= 2024.Q3.1, <= 2024.Q3.13
Отсутствует
com.liferay.portal:release.dxp.bom
>= 2024.Q2.0, <= 2024.Q2.13
Отсутствует
com.liferay.portal:release.dxp.bom
>= 2024.Q1.0, <= 2024.Q1.15
2024.Q1.16
com.liferay.portal:release.dxp.bom
<= 7.4.13.u92
Отсутствует
Связанные уязвимости
SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows template editors to bypass access validations via crafted URLs.