Security

Voltar para Security Alert

Liferay Security Alert: 2019 June

The following issue may compromise the security of your Liferay Portal Enterprise Edition (EE) or Liferay Digital Experience Platform implementation. This notification provides a description of the latest security vulnerability and recommended actions for Liferay Subscribers.

Affected Version/s

  • Liferay Digital Experience Platform 7.1
  • Liferay Digital Experience Platform 7.0
  • Liferay Portal 6.2 EE

Vulnerability Information

  • LSV-262: DoS and MiM vulnerabilities in Apache Commons HttpClient
  • LSV-408: Remote Code Execution using Web Content/DDM templates
  • LSV-449: System Settings is accessible to any user who with the update page permission
  • LSV-450: Marketplace is accessible to any user who with the update page permission
  • LSV-454: Privilege escalation via workflow definitions
  • LSV-460: RCE using JSON Deserialization in templates

Download

Please see the Help Center Security Advisories page for more information on the vulnerabilities and affected versions for each issue.

On this page