-
Type:
Bug
-
Status: Closed
-
Priority:
Major
-
Resolution: Fixed
-
Affects Version/s: 6.1 EE GA3 (6.1.30), 6.2 EE GA1 (6.2.10)
-
Component/s: Core Infrastructure, Security Vulnerability
Custom portlet plugins running in Liferay portal are partially vulnerable to a flaw discovered in JSR-286 specification - CVE-2015-1926.
An attacker could access plugin's web application resources restricted by web.xml security-constraint declaration or cause Denial Of Service.
See also https://web.liferay.com/group/customer/products/portal/security-vulnerability/lsv-153