QID 731007

Date Published: 2023-12-26

QID 731007: Liferay Portal Regular Expression Denial of Service (DoS) Vulnerability

Pattern Redirects in Liferay Portal allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
Affected Versions:
Liferay Portal 7.4.3.48 - 7.4.3.76 QID Detection Logic (Unauthenticated):

This QID checks for vulnerable version of Liferay Portal in response banner.

Successful exploit may allow remote attackers to consume an excessive amount of server resources via crafted request URLs.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution

    Vendor has released patch. For more info please refer to Liferay Portal Security Advisory

    CVEs related to QID 731007

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-33950 URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33950