Логотип exploitDog
bind:CVE-2025-43764
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43764

Количество 2

Количество 2

nvd логотип

CVE-2025-43764

4 месяца назад

Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenticated users with permissions to update Kaleo Workflows to enter a malicious Regex pattern causing their browser to hang for a very long time.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23w4-rpc6-wpcc

4 месяца назад

Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43764

Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenticated users with permissions to update Kaleo Workflows to enter a malicious Regex pattern causing their browser to hang for a very long time.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-23w4-rpc6-wpcc

Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet

0%
Низкий
4 месяца назад

Уязвимостей на страницу