Security

Back to Security Alert

Liferay Security Alert: December 2018

The following issue may compromise the security of your Liferay Portal Enterprise Edition (EE) or Liferay Digital Experience Platform implementation. This notification provides a description of the latest security vulnerability and recommended actions for Liferay Subscribers.

Affected Version/s

  • Liferay Digital Experience Platform 7.1
  • Liferay Digital Experience Platform 7.0
  • Liferay Portal 6.2 EE
  • Liferay Portal 6.1 EE

Vulnerability Information

  • LSV-383: OS Command Injection in SendMailHook
  • LSV-407: Path traversal vulnerability in templates
  • LSV-412: Registered User RCE using JSON Deserialization

Download

Please see the Help Center Security Vulnerability page for more information on the vulnerabilities and affected versions for each issue.

Additional Information - Disabling TLS 1.0

Liferay Portal 6.1 EE GA3 and 6.2 EE versions will have access to the fix for LPE-16580 (Outbound HTTPS connections do not honor https.protocols system property) in the upcoming fix packs. See further information here.

On this page