VulnerabilityModified
CVE-2020-15839
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading…
MEDIUM 6.5EPSS 2.16%
Does this matter?
Lower severity and a low EPSS score (2.16%). Track it; it rarely justifies an emergency change on its own.
Description
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- liferay/digital experience platform · liferay/liferay portal
- Source
- cve@mitre.org
References
- https://issues.liferay.com/browse/LPE-17029Vendor Advisory
- https://issues.liferay.com/browse/LPE-17055Vendor Advisory
- https://portal.liferay.dev/learn/security/known-vulnerabilitiesVendor Advisory
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119784928Vendor Advisory
- https://issues.liferay.com/browse/LPE-17029Vendor Advisory
- https://issues.liferay.com/browse/LPE-17055Vendor Advisory
- https://portal.liferay.dev/learn/security/known-vulnerabilitiesVendor Advisory
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119784928Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.