
Cloud Vulnerability DB
A community-led vulnerabilities database
By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows remote attackers to redirect users to arbitrary external URLs (NVD).
The vulnerability has been assigned a CVSS 4.0 Base Score of 5.1 (Medium) with the vector string CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. The vulnerability is classified as CWE-601: URL Redirection to Untrusted Site ('Open Redirect') (NVD).
This vulnerability allows remote attackers to redirect users to arbitrary external URLs through DNS rebinding attacks. The vulnerability affects the security of URL redirections and could potentially lead to users being directed to malicious websites (CERT-FR).
The vulnerability can be mitigated by changing the redirect URL security from IP to domain. Fixed versions are available in Liferay Portal 7.4.3.120 and Liferay DXP 2024.Q2.0 (CERT-FR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."