Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rggc-gf6w-9q73

Опубликовано: 04 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 4.6

Описание

Liferay Portal exposes sensitive user data through its Freemarker template

A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to, and potentially expose, confidential information that should remain restricted.

Пакеты

Наименование

com.liferay:com.liferay.portal.template.freemarker

maven
Затронутые версииВерсия исправления

>= 7.0.3, < 7.0.60

7.0.60

EPSS

Процентиль: 17%
0.00054
Низкий

4.6 Medium

CVSS4

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to, and potentially render, confidential information that should remain restricted.

EPSS

Процентиль: 17%
0.00054
Низкий

4.6 Medium

CVSS4

Дефекты

CWE-201