-
Type:
Bug
-
Status: Closed
-
Priority:
Major
-
Resolution: Fixed
-
Affects Version/s: 6.1 EE GA3 (6.1.30), 6.2 EE GA1 (6.2.10)
-
Component/s: Core Infrastructure, Security Vulnerability
A vulnerability with Apache Xalan-Java allows an attacker to load arbitrary classes or access external resources even if the portal property "xsl.template.secure.processing.enabled" has been set to true.
See also https://web.liferay.com/group/customer/products/portal/security-vulnerability/lsv-143