Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mf3r-6m25-3867

Опубликовано: 16 июн. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session

SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.

Пакеты

Наименование

com.liferay.portal:com.liferay.portal.kernel

maven
Затронутые версииВерсия исправления

< 38.0.0

38.0.0

EPSS

Процентиль: 41%
0.00186
Низкий

8.7 High

CVSS4

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
8 месяцев назад

SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.

EPSS

Процентиль: 41%
0.00186
Низкий

8.7 High

CVSS4

Дефекты

CWE-400