Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:06
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
References | () https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33950 - Vendor Advisory |
31 May 2023, 20:22
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-1333 | |
First Time |
Liferay
Liferay liferay Portal Liferay digital Experience Platform |
|
CPE | cpe:2.3:a:liferay:digital_experience_platform:7.4:update48:*:*:*:*:*:* cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update76:*:*:*:*:*:* |
|
References | (MISC) https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33950 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
Information
Published : 2023-05-24 17:15
Updated : 2024-11-21 08:06
NVD link : CVE-2023-33950
Mitre link : CVE-2023-33950
CVE.ORG link : CVE-2023-33950
JSON object : View
Products Affected
liferay
- liferay_portal
- digital_experience_platform
CWE
CWE-1333
Inefficient Regular Expression Complexity