QID 731007
Date Published: 2023-12-26
QID 731007: Liferay Portal Regular Expression Denial of Service (DoS) Vulnerability
Pattern Redirects in Liferay Portal allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
Affected Versions:
Liferay Portal 7.4.3.48 - 7.4.3.76
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Liferay Portal in response banner.
Successful exploit may allow remote attackers to consume an excessive amount of server resources via crafted request URLs.
Solution
Vendor has released patch. For more info please refer to Liferay Portal Security Advisory
Vendor References
CVEs related to QID 731007
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-33950 |
|