CVE-2020-15840

MEDIUM

Liferay Portal <7.3.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.

References (3)

Core 3

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (8)
com.liferay.portal/com.liferay.portal.impl 7.2.0 - 7.4.0Maven
com.liferay.portal/release.dxp.bom 0 - 7.0.10.fp93Maven
com.liferay.portal/release.portal.bom 0 - 7.3.1Maven
liferay/digital_experience_platform 7.0
liferay/digital_experience_platform 7.1
liferay/digital_experience_platform 7.2
liferay/liferay_portal 6.2
liferay/liferay_portal < 7.3.1
Published Sep 24, 2020
Tracked Since Feb 18, 2026