CVE-2020-13444
MEDIUMLiferay Portal/DXP <7.3.2/7.0-7.1-7.2 - Info Disclosure
Title source: llmDescription
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119317396
Various Sources x_refsource_confirm
https://issues.liferay.com/browse/LPE-17009
Scores
CVSS v3
6.5
EPSS
0.0025
EPSS Percentile
48.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (6)
com.liferay.portal/release.dxp.bom
7.0.0 - 7.0.10.fp92Maven
com.liferay.portal/release.portal.bom
7.0.0 - 7.3.2Maven
liferay/liferay_portal
7.1 ga1 (3 CPE variants)
liferay/liferay_portal
7.1.1 ga2
liferay/liferay_portal
7.2 ga1
liferay/liferay_portal
7.3 ga1 (2 CPE variants)
Published
Jun 10, 2020
Tracked Since
Feb 18, 2026