Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgqx-447m-wvcj

Опубликовано: 28 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.1

Описание

Liferay Portal Vulnerable to DoS via Crafted Headless API Request

Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing a request that returns a large number of objects.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

>= 7.4.0-ga1, < 7.4.3.100

7.4.3.100

EPSS

Процентиль: 37%
0.00159
Низкий

7.1 High

CVSS4

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing a request that returns a large number of objects.

EPSS

Процентиль: 37%
0.00159
Низкий

7.1 High

CVSS4

Дефекты

CWE-400