Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mg53-xr8m-86hw

Опубликовано: 07 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Open Redirect in Liferay Portal

The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

< 7.3.3

7.3.3

EPSS

Процентиль: 70%
0.00643
Низкий

7.5 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.

EPSS

Процентиль: 70%
0.00643
Низкий

7.5 High

CVSS3

Дефекты

CWE-601