Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3hf-r62c-mfrj

Опубликовано: 12 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.1

Описание

Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack

Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing queries that return a large number of objects.

Пакеты

Наименование

com.liferay:com.liferay.portal.vulcan.api

maven
Затронутые версииВерсия исправления

>= 8.0.2, < 40.2.0

40.2.0

Наименование

com.liferay:com.liferay.portal.vulcan.impl

maven
Затронутые версииВерсия исправления

>= 5.0.7, < 5.0.105

5.0.105

EPSS

Процентиль: 43%
0.00206
Низкий

7.1 High

CVSS4

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing queries that return a large number of objects.

EPSS

Процентиль: 43%
0.00206
Низкий

7.1 High

CVSS4

Дефекты

CWE-400