Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvgg-9h29-4g34

Опубликовано: 15 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Liferay Portal has Improper Validation of Specified Quantity in Input

Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions may incorrectly identify the subdomain of a domain name and create a supercookie, which allows remote attackers who control a website that share the same TLD to read cookies set by the application.

Пакеты

Наименование

com.liferay.portal:com.liferay.portal.impl

maven
Затронутые версииВерсия исправления

< 96.0.0

96.0.0

Наименование

com.liferay.portal:com.liferay.portal.kernel

maven
Затронутые версииВерсия исправления

< 130.0.1

130.0.1

EPSS

Процентиль: 27%
0.00094
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-1284

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions may incorrectly identify the subdomain of a domain name and create a supercookie, which allows remote attackers who control a website that share the same TLD to read cookies set by the application.

EPSS

Процентиль: 27%
0.00094
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-1284