Unrestricted Upload of File with Dangerous Type in Liferay Portal and Liferay DXP
Moderate severity
GitHub Reviewed
Published
Feb 10, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Package
Affected versions
<= 7.1.10.fp17
>= 7.2.1, <= 7.2.10.fp5
Patched versions
7.1.10.fp18
7.2.10.fp6
Description
Published by the National Vulnerability Database
Sep 22, 2020
Reviewed
May 3, 2021
Published to the GitHub Advisory Database
Feb 10, 2022
Last updated
Feb 1, 2023
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
References