Логотип exploitDog
bind:CVE-2025-62260
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-62260

Количество 2

Количество 2

nvd логотип

CVE-2025-62260

3 месяца назад

Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing a request that returns a large number of objects.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vgqx-447m-wvcj

3 месяца назад

Liferay Portal Vulnerable to DoS via Crafted Headless API Request

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-62260

Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing a request that returns a large number of objects.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-vgqx-447m-wvcj

Liferay Portal Vulnerable to DoS via Crafted Headless API Request

0%
Низкий
3 месяца назад

Уязвимостей на страницу