Description
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0957 | Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files. |
Github GHSA |
GHSA-c7f6-4vx5-4263 | Unrestricted Upload of File with Dangerous Type in Liferay Portal and Liferay DXP |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T13:30:22.686Z
Reserved: 2020-07-20T00:00:00.000Z
Link: CVE-2020-15839
No data.
Status : Modified
Published: 2020-09-22T18:15:23.980
Modified: 2024-11-21T05:06:17.603
Link: CVE-2020-15839
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA