Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrqm-qpw9-w8rv

Опубликовано: 25 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Liferay Portal and DXP vulnerable to a memory leak

A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API endpoint.

Пакеты

Наименование

com.liferay:com.liferay.portal.vulcan.impl

maven
Затронутые версииВерсия исправления

< 5.0.115

5.0.115

EPSS

Процентиль: 20%
0.00063
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-401

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API endpoint.

EPSS

Процентиль: 20%
0.00063
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-401