Описание
Unrestricted Upload of File with Dangerous Type in Liferay Portal and Liferay DXP
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-15839
- https://issues.liferay.com/browse/LPE-17029
- https://issues.liferay.com/browse/LPE-17055
- https://portal.liferay.dev/learn/security/known-vulnerabilities
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119784928
Пакеты
Наименование
com.liferay.portal:release.dxp.bom
maven
Затронутые версииВерсия исправления
<= 7.1.10.fp17
7.1.10.fp18
Наименование
com.liferay.portal:release.dxp.bom
maven
Затронутые версииВерсия исправления
>= 7.2.1, <= 7.2.10.fp5
7.2.10.fp6
Связанные уязвимости
CVSS3: 6.5
nvd
больше 5 лет назад
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.