Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
{
"github_reviewed_at": "2021-05-03T17:25:30Z",
"severity": "MODERATE",
"nvd_published_at": "2020-09-22T18:15:00Z",
"cwe_ids": [
"CWE-434"
],
"github_reviewed": true
}