← Back

CVE-2023-33950

nvd nist
Published: May 24, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.

Affected (3)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.4 update48
Version 7.4 update76
From 7.4.3.48 to 7.4.3.76

Timeline

No history available yet.