Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4fw-4mhr-hc45

Опубликовано: 04 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.1

Описание

Liferay Portal Vulnerable to Denial of Service in Kaleo Forms Admin

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.

Пакеты

Наименование

com.liferay:com.liferay.portal.workflow.kaleo.forms.web

maven
Затронутые версииВерсия исправления

< 5.0.29

5.0.29

EPSS

Процентиль: 70%
0.00629
Низкий

7.1 High

CVSS4

Дефекты

CWE-400

Связанные уязвимости

nvd
5 месяцев назад

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.

EPSS

Процентиль: 70%
0.00629
Низкий

7.1 High

CVSS4

Дефекты

CWE-400