5.3
CVE-2020-15840
- EPSS 1.21%
- Veröffentlicht 24.09.2020 15:15:14
- Zuletzt bearbeitet 13.05.2025 18:17:51
- Erkennungen
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version 7.0
Liferay ≫ Digital Experience Platform Version 7.1
Liferay ≫ Digital Experience Platform Version 7.2
Liferay ≫ Liferay Portal Version < 7.3.1
Liferay ≫ Liferay Portal Version 6.2 Update - SwEdition enterprise
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.21% | 0.647 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
https://portal.liferay.dev/learn/security/known-vulnerabilities
https://issues.liferay.com/browse/LPE-17046
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119772204