CVE-2023-33950

Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:liferay:digital_experience_platform:7.4:update48:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update76:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.5
References () https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33950 - Vendor Advisory () https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33950 - Vendor Advisory

31 May 2023, 20:22

Type Values Removed Values Added
CWE CWE-1333
First Time Liferay
Liferay liferay Portal
Liferay digital Experience Platform
CPE cpe:2.3:a:liferay:digital_experience_platform:7.4:update48:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update76:*:*:*:*:*:*
References (MISC) https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33950 - (MISC) https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33950 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

Information

Published : 2023-05-24 17:15

Updated : 2024-11-21 08:06


NVD link : CVE-2023-33950

Mitre link : CVE-2023-33950

CVE.ORG link : CVE-2023-33950


JSON object : View

Products Affected

liferay

  • liferay_portal
  • digital_experience_platform
CWE
CWE-1333

Inefficient Regular Expression Complexity