Security

Voltar para Security Alert

Liferay Security Alert: 2022 April

The following issue may compromise the security of your Liferay Digital Experience Platform (DXP) implementation. This notification provides a description of the latest security vulnerability and recommended actions for Liferay Subscribers.

Affected Version/s

  • Liferay Digital Experience Platform 7.4
  • Liferay Digital Experience Platform 7.3
  • Liferay Digital Experience Platform 7.2
  • Liferay Digital Experience Platform 7.1
  • Liferay Digital Experience Platform 7.0

Vulnerability Information

  • LSV-980: LDAP credentials exposed in URL

Download

The listed vulnerabilities will be fixed under DXP Security Fix Pack: 202201. DXP Security Fix Packs require the latest released Fix Pack or can be built on a specific Fix Pack level upon request. Please read the DXP Security Fix Packs article for more information and installation instructions.

For more information on the vulnerability and affected versions for the issue, please visit the Help Center Security Advisories page.

On this page