Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-62162

Load arbitrary classes and access to external resources from XSL

    Details

      Description

      A vulnerability with Apache Xalan-Java (CVE-2014-0107) allows an attacker to load arbitrary classes or access external resources even if the portal property "xsl.template.secure.processing.enabled" has been set to true.

        Attachments

          Activity

            People

            Assignee:
            samuel.kong Samuel Kong
            Reporter:
            samuel.kong Samuel Kong
            Participants of an Issue:
            Recent user:
            Esther Sanz
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Days since last comment:
              4 years, 40 weeks, 6 days ago

                Packages

                Version Package