An open API service providing security vulnerability metadata for many open source software ecosystems.

maven

com.liferay.portal:com.liferay.portal.impl

maven

Contains implementation for the portal services.

View on github.com · View on repo1.maven.org

Security Advisories for com.liferay.portal:com.liferay.portal.impl in maven

Moderate
about 1 month ago

Liferay Portal and DXP use an incorrect cache-control header GSA_kwCzR0hTQS02NTMzLWZocjItZjM4aM4ABOHY

maven com.liferay.portal:com.liferay.portal.impl, com.liferay:com.liferay.adaptive.media.web
Moderate
about 1 month ago

Liferay Portal Stores Password Reset Tokens in Plain Text GSA_kwCzR0hTQS14Y2o2LXhwamctYzR4cs4ABN5f

maven com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom
Moderate
2 months ago

Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet GSA_kwCzR0hTQS0yaG03LXI4ZjMtNDIzaM4ABMw8

maven com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom
Moderate
3 months ago

Liferay Portal Cross-Site Request Forgery (CSRF) vulnerability GSA_kwCzR0hTQS02OTdoLTNxNm0tandwNM4ABMZX

maven com.liferay.portal:com.liferay.portal.impl
Moderate
3 months ago

Liferay Portal has Improper Validation of Specified Quantity in Input GSA_kwCzR0hTQS14dmdnLTloMjktNGczNM4ABMIU

maven com.liferay.portal:com.liferay.portal.kernel, com.liferay.portal:com.liferay.portal.impl
Moderate
4 months ago

Liferay Portal JSONWS API endpoint shares sensitive information GSA_kwCzR0hTQS1jdjlqLW1nOXctdjd3bc4ABLYM

maven com.liferay.portal:com.liferay.portal.impl
Moderate
4 months ago

Liferay Portal and Liferay DXP have a reflected cross-site scripting vulnerability GSA_kwCzR0hTQS0yMjJ3LXhtYzUtamhwM84ABK8q

maven com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
almost 2 years ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page GSA_kwCzR0hTQS1taDlyLTlwY3gtcng1Nc4AA5Z6

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:com.liferay.portal.impl
Moderate
about 3 years ago

Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled GSA_kwCzR0hTQS05NDI3LTdmNjUtODhjOM4AAvMO

maven com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom
High
over 3 years ago

Liferay Portal and Liferay DXP fails to invalidate password reset tokens after use GSA_kwCzR0hTQS12d2o4LTRncmYtM3I4ds4AArKO

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:com.liferay.portal.impl
High
over 3 years ago

Liferay Portal and Liferay DXP insecure default configuration GSA_kwCzR0hTQS1qZmNoLW0yeDMtMnY2Ns4AApYW

maven com.liferay.portal:release.portal.bom, com.liferay.portal:com.liferay.portal.impl
Moderate
over 3 years ago

Liferay Portal and Liferay DXP Bypass via Double Encoded URL GSA_kwCzR0hTQS12cnd4LXE5cGoteDQ4OM4AAmDc

maven com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Moderate
over 3 years ago

Liferay Portal and Liferay DXP fails to check permissions to view sites/groups GSA_kwCzR0hTQS04MjJmLWpmcGctaGc3aM09mw

maven com.liferay.portal:com.liferay.portal.impl, com.liferay:com.liferay.site.browser.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom

Filter by Severity