QID 997169
Date Published: 2024-02-09
QID 997169: Java (Maven) Security Update for com.liferay.portal:release.dxp.bom (GHSA-mqf8-4cqm-p83x)
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote attackers to discover the existence of sites by enumerating URLs. This vulnerability occurs if locale.prepend.friendly.url.style=2 and if a custom 404 page is used.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-mqf8-4cqm-p83x for updates and patch information.
Vendor References
- GHSA-mqf8-4cqm-p83x -
github.com/advisories/GHSA-mqf8-4cqm-p83x
CVEs related to QID 997169
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mqf8-4cqm-p83x | com.liferay.portal:release.dxp.bom |
|