GHSA-mg53-xr8m-86hw

Suggest an improvement
Source
https://github.com/advisories/GHSA-mg53-xr8m-86hw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-mg53-xr8m-86hw/GHSA-mg53-xr8m-86hw.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-mg53-xr8m-86hw
Aliases
Published
2021-05-07T15:54:54Z
Modified
2023-11-01T04:52:36.227744Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Open Redirect in Liferay Portal
Details

The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.

Database specific
{
    "nvd_published_at": "2020-09-01T14:15:00Z",
    "github_reviewed_at": "2021-05-05T19:14:04Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-601"
    ]
}
References

Affected packages

Maven / com.liferay.portal:release.portal.bom

Package

Name
com.liferay.portal:release.portal.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.portal.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.3.3

Affected versions

7.*

7.0.6
7.0.6-1
7.0.6-2
7.1.0
7.1.1
7.1.2
7.1.3
7.1.3-1
7.2.0
7.2.1
7.2.1-1
7.3.0
7.3.0-1
7.3.1
7.3.1-1
7.3.2
7.3.2-1