CVE-2020-15839
Last modified
CVE-2020-15839 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.. EPSS estimates a 2.16% chance of exploitation in the next 30 days.
Description
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Liferay | Digital Experience Platform | 7.1 |
| Liferay | Digital Experience Platform | 7.2 |
| Liferay | Liferay Portal | < 7.3.3 |
References
- https://issues.liferay.com/browse/LPE-17029Vendor Advisory
- https://issues.liferay.com/browse/LPE-17055Vendor Advisory
- https://issues.liferay.com/browse/LPE-17029Vendor Advisory
- https://issues.liferay.com/browse/LPE-17055Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15839?
How severe is CVE-2020-15839?
How do I fix CVE-2020-15839?
Are you affected by CVE-2020-15839?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
