Skip to content

Commit 2a150ec

Browse files
1 parent 5e9aaab commit 2a150ec

File tree

3 files changed

+6
-6
lines changed

3 files changed

+6
-6
lines changed

advisories/github-reviewed/2025/10/GHSA-pfxj-gvqg-mj44/GHSA-pfxj-gvqg-mj44.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-pfxj-gvqg-mj44",
4-
"modified": "2025-10-07T22:06:10Z",
4+
"modified": "2025-12-17T00:11:39Z",
55
"published": "2025-10-07T00:31:11Z",
66
"aliases": [
77
"CVE-2025-43824"
88
],
99
"summary": "Liferay Profile Widget does not prevent vCard extension spoofing",
10-
"details": "The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.",
10+
"details": "The Profile Widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.",
1111
"severity": [
1212
{
1313
"type": "CVSS_V4",

advisories/github-reviewed/2025/10/GHSA-rggc-gf6w-9q73/GHSA-rggc-gf6w-9q73.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-rggc-gf6w-9q73",
4-
"modified": "2025-10-07T12:59:19Z",
4+
"modified": "2025-12-17T00:11:09Z",
55
"published": "2025-10-04T00:32:21Z",
66
"aliases": [
77
"CVE-2025-43825"
88
],
99
"summary": "Liferay Portal exposes sensitive user data through its Freemarker template",
10-
"details": "A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to, and potentially render, confidential information that should remain restricted.",
10+
"details": "A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to, and potentially expose, confidential information that should remain restricted.",
1111
"severity": [
1212
{
1313
"type": "CVSS_V4",

advisories/github-reviewed/2025/10/GHSA-xx7h-2wf7-hc7p/GHSA-xx7h-2wf7-hc7p.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-xx7h-2wf7-hc7p",
4-
"modified": "2025-10-09T14:18:55Z",
4+
"modified": "2025-12-17T00:12:01Z",
55
"published": "2025-10-08T00:31:07Z",
66
"aliases": [
77
"CVE-2025-43823"
88
],
99
"summary": "Liferay Portal is vulnerable to XSS through its Commerce Search Result widget",
10-
"details": "Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4 before patch 6, 2023.Q3 before patch 9, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Commerce Product's Name text field.",
10+
"details": "Cross-site Scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4 before patch 6, 2023.Q3 before patch 9, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Commerce Product's Name text field.",
1111
"severity": [
1212
{
1313
"type": "CVSS_V4",

0 commit comments

Comments
 (0)