Details
-
Bug
-
Status: Closed
-
Critical
-
Resolution: Fixed
-
6.1 EE GA3 (6.1.30), 6.2 EE GA1 (6.2.10), 7.0 DE (7.0.10)
-
5
Description
PDFBox is vulnerable to XML External Entity (XXE) attacks (CVE-2016-2175). This vulnerability can allow an attacker to access files on file system or to take down the portal.
Please visit https://web.liferay.com/group/customer/products/portal/security-vulnerability/lsv-242 for more information.