From ba1e07cd036e6a1be1edd71169ae9994e80b9544 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 21 Feb 2024 23:29:57 +0000 Subject: [PATCH] Publish Advisories GHSA-43v2-6grp-9pp9 GHSA-p28x-4r5h-ph6j GHSA-v2xq-m22w-jmpr GHSA-xpjg-7hx7-wgcx GHSA-43v2-6grp-9pp9 GHSA-p28x-4r5h-ph6j GHSA-v2xq-m22w-jmpr GHSA-xpjg-7hx7-wgcx --- .../GHSA-43v2-6grp-9pp9.json | 150 ++++++++++++++++++ .../GHSA-p28x-4r5h-ph6j.json | 99 ++++++++++++ .../GHSA-v2xq-m22w-jmpr.json | 99 ++++++++++++ .../GHSA-xpjg-7hx7-wgcx.json | 99 ++++++++++++ .../GHSA-43v2-6grp-9pp9.json | 103 ------------ .../GHSA-p28x-4r5h-ph6j.json | 38 ----- .../GHSA-v2xq-m22w-jmpr.json | 38 ----- .../GHSA-xpjg-7hx7-wgcx.json | 38 ----- 8 files changed, 447 insertions(+), 217 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-43v2-6grp-9pp9/GHSA-43v2-6grp-9pp9.json create mode 100644 advisories/github-reviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json create mode 100644 advisories/github-reviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json create mode 100644 advisories/github-reviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-43v2-6grp-9pp9/GHSA-43v2-6grp-9pp9.json delete mode 100644 advisories/unreviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json delete mode 100644 advisories/unreviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json delete mode 100644 advisories/unreviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json diff --git a/advisories/github-reviewed/2022/05/GHSA-43v2-6grp-9pp9/GHSA-43v2-6grp-9pp9.json b/advisories/github-reviewed/2022/05/GHSA-43v2-6grp-9pp9/GHSA-43v2-6grp-9pp9.json new file mode 100644 index 00000000000..47fe7da2555 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-43v2-6grp-9pp9/GHSA-43v2-6grp-9pp9.json @@ -0,0 +1,150 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43v2-6grp-9pp9", + "modified": "2024-02-21T23:28:17Z", + "published": "2022-05-14T02:56:35Z", + "aliases": [ + "CVE-2011-0534" + ], + "summary": "Apache Tomcat does not enforce the maxHttpHeaderSize limit", + "details": "Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat:tomcat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "6.0.0" + }, + { + "fixed": "6.0.32" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 6.0.30" + } + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat:tomcat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.0.0" + }, + { + "fixed": "7.0.8" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 7.0.6" + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-0534" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/008447095ce8c3a8f713093d5e618f3f06f94ea8" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65162" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/tomcat" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT5002" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20110801035315/http://secunia.com/advisories/45022" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20120120085637/http://securityreason.com/securityalert/8074" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20121024140440/http://secunia.com/advisories/43192" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20121212040149/http://www.securitytracker.com/id?1025027" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20131227020011/http://www.securityfocus.com/bid/46164" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20151017023138/http://secunia.com/advisories/57126" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20200517155748/http://www.securityfocus.com/archive/1/516214/100/0/threaded" + }, + { + "type": "WEB", + "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" + }, + { + "type": "WEB", + "url": "http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html" + }, + { + "type": "WEB", + "url": "http://marc.info/?l=bugtraq&m=139344343412337&w=2" + }, + { + "type": "WEB", + "url": "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5098550.html" + }, + { + "type": "WEB", + "url": "http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.32" + }, + { + "type": "WEB", + "url": "http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.8_(released_5_Feb_2011)" + }, + { + "type": "WEB", + "url": "http://www.debian.org/security/2011/dsa-2160" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:28:16Z", + "nvd_published_at": "2011-02-10T18:00:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json b/advisories/github-reviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json new file mode 100644 index 00000000000..162a0e708d5 --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p28x-4r5h-ph6j", + "modified": "2024-02-21T23:28:35Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-25152" + ], + "summary": "Liferay Portal Message Board widget and Liferay DXP vulnerable to stored Cross-site Scripting", + "details": "Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the filename of an attachment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "7.4.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.0" + }, + { + "fixed": "7.3.10.u4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.2.10.fp17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25152" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25152" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:28:34Z", + "nvd_published_at": "2024-02-21T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json b/advisories/github-reviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json new file mode 100644 index 00000000000..da3a1bcea4f --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2xq-m22w-jmpr", + "modified": "2024-02-21T23:29:21Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-25602" + ], + "summary": "Liferay Portal and Liferay DXP's Users Admin module vulnerable to stored Cross-site Scripting", + "details": "Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into an organization’s “Name” text field", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "7.4.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.0" + }, + { + "fixed": "7.3.10.u4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.2.10.fp17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25602" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25602" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:29:21Z", + "nvd_published_at": "2024-02-21T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json b/advisories/github-reviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json new file mode 100644 index 00000000000..09b7fe247fc --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpjg-7hx7-wgcx", + "modified": "2024-02-21T23:28:50Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-25147" + ], + "summary": "Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting", + "details": "Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "7.4.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.0" + }, + { + "fixed": "7.3.10.u4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.2.10.fp15" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25147" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:28:50Z", + "nvd_published_at": "2024-02-21T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-43v2-6grp-9pp9/GHSA-43v2-6grp-9pp9.json b/advisories/unreviewed/2022/05/GHSA-43v2-6grp-9pp9/GHSA-43v2-6grp-9pp9.json deleted file mode 100644 index b74d5026b0f..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-43v2-6grp-9pp9/GHSA-43v2-6grp-9pp9.json +++ /dev/null @@ -1,103 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-43v2-6grp-9pp9", - "modified": "2022-05-14T02:56:35Z", - "published": "2022-05-14T02:56:35Z", - "aliases": [ - "CVE-2011-0534" - ], - "details": "Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-0534" - }, - { - "type": "WEB", - "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65162" - }, - { - "type": "WEB", - "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" - }, - { - "type": "WEB", - "url": "http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html" - }, - { - "type": "WEB", - "url": "http://marc.info/?l=bugtraq&m=139344343412337&w=2" - }, - { - "type": "WEB", - "url": "http://osvdb.org/70809" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/43192" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/45022" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/57126" - }, - { - "type": "WEB", - "url": "http://securityreason.com/securityalert/8074" - }, - { - "type": "WEB", - "url": "http://support.apple.com/kb/HT5002" - }, - { - "type": "WEB", - "url": "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5098550.html" - }, - { - "type": "WEB", - "url": "http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.32" - }, - { - "type": "WEB", - "url": "http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.8_(released_5_Feb_2011)" - }, - { - "type": "WEB", - "url": "http://www.debian.org/security/2011/dsa-2160" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/516214/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/46164" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1025027" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2011/0293" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2011-02-10T18:00:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json b/advisories/unreviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json deleted file mode 100644 index 438f2daa7c3..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-p28x-4r5h-ph6j/GHSA-p28x-4r5h-ph6j.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-p28x-4r5h-ph6j", - "modified": "2024-02-21T03:30:37Z", - "published": "2024-02-21T03:30:37Z", - "aliases": [ - "CVE-2024-25152" - ], - "details": "Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the filename of an attachment.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25152" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25152" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-21T02:15:29Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json b/advisories/unreviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json deleted file mode 100644 index 188af34d91e..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-v2xq-m22w-jmpr/GHSA-v2xq-m22w-jmpr.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-v2xq-m22w-jmpr", - "modified": "2024-02-21T03:30:37Z", - "published": "2024-02-21T03:30:37Z", - "aliases": [ - "CVE-2024-25602" - ], - "details": "Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into an organization’s “Name” text field", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25602" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25602" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-21T02:15:30Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json b/advisories/unreviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json deleted file mode 100644 index 41afc0b0cb7..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-xpjg-7hx7-wgcx/GHSA-xpjg-7hx7-wgcx.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-xpjg-7hx7-wgcx", - "modified": "2024-02-21T03:30:37Z", - "published": "2024-02-21T03:30:37Z", - "aliases": [ - "CVE-2024-25147" - ], - "details": "Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25147" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25147" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-21T02:15:29Z" - } -} \ No newline at end of file