Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cw79-fq4f-9r96

Опубликовано: 27 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 4.6

Описание

Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature

Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email address in the log files.

Пакеты

Наименование

com.liferay:com.liferay.portal.security.ldap.impl

maven
Затронутые версииВерсия исправления

>= 4.0.2, < 4.0.54

4.0.54

EPSS

Процентиль: 3%
0.00017
Низкий

4.6 Medium

CVSS4

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 4.4
nvd
3 месяца назад

Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email address in the log files.

EPSS

Процентиль: 3%
0.00017
Низкий

4.6 Medium

CVSS4

Дефекты

CWE-532