Uploaded image for project: 'PUBLIC - Liferay Portal Enterprise Edition'
  1. PUBLIC - Liferay Portal Enterprise Edition
  2. LPE-3810

Users can access files in a portlet's META-INF or WEB-INF folder

    Details

      Description

      Users can access files in a portlet's META-INF or WEB-INF folder. This issue was previously fixed for all Liferay plugins in LPE-2960. However, the old solution required plugin portlet developers to individually patch their plugin. This updated solution fixes the security hole for all plugins.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              samuel.kong Samuel Kong
              Reporter:
              brian.chan Brian Chan
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Packages

                  Version Package
                  5.1 EE SP6 (5.1.9)
                  5.2 EE SP6 (5.2.10)
                  6.0 EE SP1 (6.0.11)