CVE-2020-13444
published 2020-06-10CVE-2020-13444: Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.59%
73.0th percentile
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal and Liferay DXP Fails to Sanitize API Data
ghsa·2022-05-24
CVE-2020-13444 [MEDIUM] CWE-200 Liferay Portal and Liferay DXP Fails to Sanitize API Data
Liferay Portal and Liferay DXP Fails to Sanitize API Data
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 19, and 7.2 before fix pack 7, does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
OSV
Liferay Portal and Liferay DXP Fails to Sanitize API Data
osv·2022-05-24
CVE-2020-13444 [MEDIUM] Liferay Portal and Liferay DXP Fails to Sanitize API Data
Liferay Portal and Liferay DXP Fails to Sanitize API Data
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 19, and 7.2 before fix pack 7, does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://issues.liferay.com/browse/LPE-17009https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119317396https://issues.liferay.com/browse/LPE-17009https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119317396
2020-06-10
Published